VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying an oversized string in the directory field. Attackers can craft a malicious input file containing 271 bytes of junk data followed by a return address to execute arbitrary code with application privileges.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 17 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vxsearch
Vxsearch vx Search |
|
| Vendors & Products |
Vxsearch
Vxsearch vx Search |
Sun, 17 May 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | VX Search 10.6.18 contains a local buffer overflow vulnerability that allows attackers to overwrite the instruction pointer by supplying an oversized string in the directory field. Attackers can craft a malicious input file containing 271 bytes of junk data followed by a return address to execute arbitrary code with application privileges. | |
| Title | VX Search 10.6.18 Local Buffer Overflow via Directory Field | |
| First Time appeared |
Webberzone
Webberzone better Search |
|
| Weaknesses | CWE-120 | |
| CPEs | cpe:2.3:a:webberzone:better_search:10.6.18:*:*:*:*:*:*:* | |
| Vendors & Products |
Webberzone
Webberzone better Search |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-17T12:11:33.848Z
Reserved: 2026-05-17T11:42:36.674Z
Link: CVE-2018-25328
No data.
Status : Received
Published: 2026-05-17T13:16:44.310
Modified: 2026-05-17T13:16:44.310
Link: CVE-2018-25328
No data.
OpenCVE Enrichment
Updated: 2026-05-17T14:30:03Z
Weaknesses