SurfOffline Professional 2.2.0.103 contains a structured...
Moderate severity
Unreviewed
Published
Feb 13, 2026
to the GitHub Advisory Database
•
Updated Feb 13, 2026
Description
Published by the National Vulnerability Database
Feb 12, 2026
Published to the GitHub Advisory Database
Feb 13, 2026
Last updated
Feb 13, 2026
SurfOffline Professional 2.2.0.103 contains a structured exception handler (SEH) overflow vulnerability that allows attackers to crash the application by manipulating the project name input. Attackers can generate a malicious payload of 382 'A' characters followed by specific byte sequences to trigger a denial of service condition and overwrite SEH registers.
References