PatchSiren

EcoSearch CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM EcoSearch CVE published 2026-04-04

CVE-2018-25244

CVE-2018-25244 is a denial of service vulnerability in Eco Search 1.0.2.0. Local attackers can crash the application by submitting an excessively long string to the search functionality. The vulnerability exists due to the application's search functionality not properly handling excessively long strings. An attacker can paste a buffer of 950 or more characters into the search bar and trigger a crash by in [truncated]