CVE-2019-25602
GSearch 1.0.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting an excessively long string in the search bar. Attackers can paste a buffer of 2000 characters into the search field, click search, and select any result to trigger an application crash.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.8
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.11%
- CWE
- CWE-1260
- Published
- 2026-03-22
- Last modified
- 2026-03-23
Affected products
- GSearch GSearch
Weakness type
Related vulnerabilities
- CVE-2025-31936 — Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors...
- CVE-2026-20760 — Improper handling of overlap between protected memory ranges in some microcode for some Intel(R)...
- CVE-2018-25240 — Watchr 1.1.0.0 Denial of Service via Search
- CVE-2018-25238 — VSCO 1.1.1.0 Denial of Service via Search
- CVE-2019-25592 — PHPRunner 10.1 Denial of Service via Dashboard Name Field
- CVE-2019-25585 — Deluge 1.3.15 Denial of Service via Webseeds Field
- CVE-2019-25572 — NordVPN 6.19.6 Denial of Service via Email Field Buffer Overflow
- CVE-2019-25570 — RealTerm Serial Terminal 2.0.0.70 Denial of Service via Port Field