CVE-2018-25242

One Search 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar to trigger an unhandled exception that crashes the application.
Configurations

No configuration.

History

21 Jul 2026, 07:10

Type Values Removed Values Added
Summary
  • (es) One Search 1.1.0.0 contiene una vulnerabilidad de denegación de servicio que permite a atacantes locales bloquear la aplicación al enviar cadenas de entrada excesivamente largas a la funcionalidad de búsqueda. Los atacantes pueden pegar un búfer de 950 o más caracteres en la barra de búsqueda para activar una excepción no controlada que bloquea la aplicación.

04 Apr 2026, 20:16

Type Values Removed Values Added
References
  • {'url': 'https://www.vulncheck.com/advisories/microsoft-one-search-denial-of-service', 'source': 'disclosure@vulncheck.com'}
  • () https://www.vulncheck.com/advisories/one-search-denial-of-service -

04 Apr 2026, 17:16

Type Values Removed Values Added
Summary (en) Microsoft One Search 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar to trigger an unhandled exception that crashes the application. (en) One Search 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting excessively long input strings to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar to trigger an unhandled exception that crashes the application.

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-07-21 07:10


NVD link : CVE-2018-25242

Mitre link : CVE-2018-25242

CVE.ORG link : CVE-2018-25242


JSON object : View

Products Affected

No product.

CWE
CWE-1389

Incorrect Parsing of Numbers with Different Radices