CVE-2019-6991: Zoneminder

Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.

A classic Stack-based buffer overflow exists in the zmLoadUser() function in zm_user.cpp of the zmu binary in ZoneMinder through 1.32.3, allowing an unauthenticated attacker to execute code via a long username.

Affected products

Published 2019-01-28. Last modified 2026-06-17.