CVE-2018-25240
Microsoft Watchr 1.1.0.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting an excessively long string to the search functionality. Attackers can paste a buffer of 8145 characters into the search bar and trigger a search operation to cause the application to crash.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.9
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.12%
- CWE
- CWE-1260
- Published
- 2026-04-04
- Last modified
- 2026-04-07
Affected products
- Watchr Watchr
Weakness type
Related vulnerabilities
- CVE-2025-31936 — Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors...
- CVE-2026-20760 — Improper handling of overlap between protected memory ranges in some microcode for some Intel(R)...
- CVE-2018-25238 — VSCO 1.1.1.0 Denial of Service via Search
- CVE-2019-25602 — GSearch 1.0.1.0 Denial of Service via Search Input
- CVE-2019-25592 — PHPRunner 10.1 Denial of Service via Dashboard Name Field
- CVE-2019-25585 — Deluge 1.3.15 Denial of Service via Webseeds Field
- CVE-2019-25572 — NordVPN 6.19.6 Denial of Service via Email Field Buffer Overflow
- CVE-2019-25570 — RealTerm Serial Terminal 2.0.0.70 Denial of Service via Port Field