Junglewise Threat Intelligence

CVE-2018-25378: Stoked On It Notebook Pro denial of service in notebook name field

CVE-2018-25378 · Severity: medium · CVSS 6.2 · Published 2026-05-25

Executive brief

Notebook Pro, a note-taking application for Windows, is vulnerable to a flaw that allows a user to crash the software. By entering an unusually long name when creating a new notebook, an attacker can cause the application to stop responding or shut down unexpectedly. This impact is limited to the availability of the application on the local machine and does not involve the theft of personal data.

Technical details

A denial of service vulnerability exists in Notebook Pro 2.0 due to improper handling of input length in the 'New Notebook Name' field. The root cause is categorized as CWE-789 (Memory Allocation with Excessive Size Value), where the application fails to validate the length of the notebook name before processing. A local attacker can trigger this by pasting a string of 500 or more characters into the name field and attempting to save the notebook, resulting in an immediate application crash. The vulnerability was verified on Windows 10 64-bit systems. No patch is currently specified in the advisory, though the issue was publicly disclosed with a proof-of-concept script.

Affected products

  • Stoked On It Notebook Pro 2.0

Timeline

  • 2018-09-14: disclosed: Vulnerability discovered and PoC developed by researcher Ali Alipour.
  • 2018-09-17: other: Exploit published on Exploit-DB.
  • 2026-05-25: advisory: CVE-2018-25378 published/updated in NVD.

References