CVE-2020-37190
Awaiting Analysis
Awaiting Analysis - Queue
Denial of Service via Input Overflow in Top Password Firefox
Publication date: 2026-02-11
Last updated on: 2026-02-12
Assigner: VulnCheck
Description
Description
Top Password Firefox Password Recovery 2.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting 5000 characters into the User Name or Registration Code input fields.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| top-password | firefox_password_recovery | 2.8 |
| top-password | pcunlocker | * |
| top-password | keyfinder_plus | * |
| top-password | outlook_password_recovery | * |
| top-password | sql_server_password_changer | * |
| top-password | protect_my_folders | * |
| top_password | firefox_password_recovery | 2.8 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-120 | The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer. |