CVE-2019-6991: Zoneminder
Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.
A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an unauthenticated attacker to execute code via a long username.
Affected products
- Zoneminder Zoneminder: up to and including 1.32.3
Published 2019-01-28. Last modified 2026-06-17.