Sticky Notes and Color Widgets Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in Sticky Notes & Color Widgets version 1.4.2. This issue allows attackers to crash the application by creating notes with excessively long character strings. By pasting large payloads of repeated characters into note fields, the application becomes unresponsive and eventually crashes.

Impact

Exploitation of this vulnerability leads to application crashes, causing the app to stop responding and disrupt user activity.

Reproduction

To reproduce this vulnerability, open the Sticky Notes & Color Widgets application and create a new note. Then, run a Python script that generates a text file containing a long string of repeated characters. After the file is created, copy its contents and paste them into the note twice. This action will cause the application to crash.

Added: May 16, 2026, 4:23 PM
Updated: May 16, 2026, 4:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
8.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.