Impact
GSearch 1.0.1.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting an excessively long string in the search bar. Attackers can paste a buffer of 2000 characters, click search, and select any result to trigger a crash. The vulnerability does not lead to data disclosure or modification; it purely causes the application to terminate.
Affected Systems
Affected product is GSearch version 1.0.1.0. No other versions or vendors are indicated to be vulnerable, and the CNA vendor list lists only GSearch. Only local users with access to the application can trigger the issue.
Risk and Exploitability
The CVSS score is 6.8, indicating moderate severity. Exploitation requires local access and does not involve remote code execution or privilege escalation. EPSS score is not available, and the vulnerability is not in KEV. Attackers can trigger the crash by using the search field, but no confidentiality, integrity, or remote execution impact is present. Immediate patching is recommended due to moderate score and ease of exploitation.
OpenCVE Enrichment