SpotAuditor Buffer Overflow Vulnerability in Base64 Password Decoder Component Leading to Denial-of-Service

Vulnerability

A local buffer overflow vulnerability has been identified in SpotAuditor version 3.6.7, specifically within the Base64 Password Decoder component. This vulnerability allows attackers to cause a denial-of-service condition by supplying an oversized Base64 string through the decoder interface, which crashes the application.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to crash.

Reproduction

To reproduce this vulnerability, first run SpotAuditor 3.6.7. Then, navigate to the 'Tools' menu and select 'Base64 Password Decoder'. Paste an oversized Base64 string into the 'Base64 Encrypted Password' textbox and click the 'Decrypt' button. The application will crash, demonstrating the denial-of-service condition.

Added: Apr 5, 2026, 9:18 PM
Updated: Apr 5, 2026, 9:18 PM

Vulnerability Rating

Custom Algorithm
spread
1.2
impact
2.5
exploitability
4.6
remediation
0.0
relevance
5.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.