CVE-2018-25244

Eco Search 1.0.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar and trigger a crash by initiating a search operation.
Configurations

No configuration.

History

04 Apr 2026, 20:16

Type Values Removed Values Added
References
  • {'url': 'https://www.vulncheck.com/advisories/microsoft-eco-search-denial-of-service', 'source': 'disclosure@vulncheck.com'}
  • () https://www.vulncheck.com/advisories/eco-search-denial-of-serviceĀ -

04 Apr 2026, 17:16

Type Values Removed Values Added
Summary (en) Microsoft Eco Search 1.0.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar and trigger a crash by initiating a search operation. (en) Eco Search 1.0.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 950 or more characters into the search bar and trigger a crash by initiating a search operation.

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-06-17 01:55


NVD link : CVE-2018-25244

Mitre link : CVE-2018-25244

CVE.ORG link : CVE-2018-25244


JSON object : View

Products Affected

No product.

CWE
CWE-1312

Missing Protection for Mirrored Regions in On-Chip Fabric Firewall