CVE-2019-25620CWE-168

Tree Studio 2.17 Denial of Service via Malformed Input

Medium · published March 23, 2026

CVSS v4.0
6.9
EPSS
0%
Percentile
7.0
In the wild
Unconfirmed
What it is

Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.

The record
Technical detail
CVSS v4.0
6.9 · MEDIUM
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00174 · 7.0th percentile
Weakness
CWE-168 · Improper Handling of Inconsistent Special Elements
Published
2026-03-23T13:48Z
EPSS history
Timeline
  • 23 MAR 13:48Z
    Tree Studio 2.17 Denial of Service via Malformed Input
    cvelistv5