VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying an oversized string in the directory field. Attackers can craft a malicious input file containing 271 bytes of junk data followed by a return address to execute arbitrary code with application privileges.
Metrics
Affected Vendors & Products
References
History
Sun, 17 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vxsearch
Vxsearch vx Search |
|
| Vendors & Products |
Vxsearch
Vxsearch vx Search |
Sun, 17 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying an oversized string in the directory field. Attackers can craft a malicious input file containing 271 bytes of junk data followed by a return address to execute arbitrary code with application privileges. | |
| Title | VX Search 10.6.18 Local Buffer Overflow via Directory Field | |
| First Time appeared |
Webberzone
Webberzone better Search |
|
| Weaknesses | CWE-120 | |
| CPEs | cpe:2.3:a:webberzone:better_search:10.6.18:*:*:*:*:*:*:* | |
| Vendors & Products |
Webberzone
Webberzone better Search |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-17T12:11:33.848Z
Reserved: 2026-05-17T11:42:36.674Z
Link: CVE-2018-25328
No data.
Status : Received
Published: 2026-05-17T13:16:44.310
Modified: 2026-05-17T13:16:44.310
Link: CVE-2018-25328
No data.
OpenCVE Enrichment
Updated: 2026-05-17T14:30:03Z