Sticky Notes and Color Widgets Denial-of-Service Vulnerability
Vulnerability
A denial-of-service vulnerability has been identified in Sticky Notes & Color Widgets version 1.4.2. This issue allows attackers to crash the application by creating notes with excessively long character strings. By pasting large payloads of repeated characters into note fields, the application becomes unresponsive and eventually crashes.
Impact
Exploitation of this vulnerability leads to application crashes, causing the app to stop responding and disrupt user activity.
Reproduction
To reproduce this vulnerability, open the Sticky Notes & Color Widgets application and create a new note. Then, run a Python script that generates a text file containing a long string of repeated characters. After the file is created, copy its contents and paste them into the note twice. This action will cause the application to crash.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
