Junglewise Threat Intelligence

CVE-2020-37196: Nsasoft Dnss Domain Name Search Software buffer overflow in registration key

CVE-2020-37196 · Severity: high · CVSS 7.5 · Published 2026-02-11

Vendors: Nsasoft.

Executive brief

Dnss Domain Name Search Software, a tool used for identifying available domain names, is vulnerable to a denial-of-service attack. An attacker can cause the application to crash by entering an excessively long registration key into the software's activation field. This prevents legitimate users from using the software until it is restarted.

Technical details

A classic buffer overflow (CWE-120) exists in Dnss Domain Name Search Software due to insufficient input validation in the registration key field. An attacker can trigger this vulnerability by inputting a 1000-character buffer into the 'Enter Registration Code' dialog. This results in an application crash (Denial of Service). While the attack requires local interaction to paste the payload, some CVSS assessments categorize this as a network-based vector if the software is used in a shared environment. No patch is currently documented in the advisory, though the vulnerability was publicly disclosed with a Proof of Concept (PoC).

Affected products

  • Nsasoft (Nsauditor) Dnss Domain Name Search Software All versions

Timeline

  • 2020-01-06: disclosed: Initial exploit PoC published on Exploit-DB
  • 2026-02-11: advisory: CVE published/updated in NVD

References

Related threats