CVE-2018-25241

VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of characters into the search bar to trigger an unhandled exception that terminates the application.
Configurations

No configuration.

History

21 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) VPN Navegador+ 1.1.0.0 contiene una vulnerabilidad de denegación de servicio que permite a atacantes no autenticados bloquear la aplicación al enviar una entrada de tamaño excesivo a través de la funcionalidad de búsqueda. Los atacantes pueden pegar un búfer grande de caracteres en la barra de búsqueda para activar una excepción no controlada que finaliza la aplicación.

04 Apr 2026, 20:16

Type Values Removed Values Added
References
  • {'url': 'https://www.vulncheck.com/advisories/microsoft-vpn-browser-denial-of-service', 'source': 'disclosure@vulncheck.com'}
  • () https://www.vulncheck.com/advisories/vpn-browser-denial-of-service -

04 Apr 2026, 17:16

Type Values Removed Values Added
Summary (en) Microsoft VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of characters into the search bar to trigger an unhandled exception that terminates the application. (en) VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of characters into the search bar to trigger an unhandled exception that terminates the application.

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-07-21 07:10


NVD link : CVE-2018-25241

Mitre link : CVE-2018-25241

CVE.ORG link : CVE-2018-25241


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function