CVE-2020-37188: Nsasoft Nsauditor Spotoutlook
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can overwrite the buffer by pasting 1000 'A' characters into the 'Name' field, causing the application to become unresponsive.
Affected products
- Nsasoft Nsauditor Spotoutlook: version 1.2.6 only
Published 2026-02-11. Last modified 2026-06-17.