Notepad-plus-plus

Notepad++

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht Exploit
  • EPSS 0.01%
  • Veröffentlicht 18.02.2026 23:07:36
  • Zuletzt bearbeitet 19.02.2026 18:32:34

Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explo...

Warnung
  • EPSS 3.93%
  • Veröffentlicht 03.02.2026 01:15:57
  • Zuletzt bearbeitet 13.02.2026 14:03:47

Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect upd...

  • EPSS 0.03%
  • Veröffentlicht 23.06.2025 19:01:16
  • Zuletzt bearbeitet 24.12.2025 15:16:01

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executa...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 30.11.2023 21:15:08
  • Zuletzt bearbeitet 21.11.2024 08:30:17

An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.

  • EPSS 0.03%
  • Veröffentlicht 30.11.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:43:47

A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file dbghelp.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 25.08.2023 21:15:08
  • Zuletzt bearbeitet 21.11.2024 08:18:54

Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `nsCodingStateMachine::NextStater`. The exploitability of this issue is not clear. Potentially, it may be used to leak i...

Exploit
  • EPSS 0.1%
  • Veröffentlicht 25.08.2023 21:15:08
  • Zuletzt bearbeitet 21.11.2024 08:18:54

Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectLanguageFromTextBegining `. The exploitability of this issue is not clear. Potentially, it may be used...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 25.08.2023 20:15:08
  • Zuletzt bearbeitet 21.11.2024 08:18:33

Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 25.08.2023 20:15:08
  • Zuletzt bearbeitet 21.11.2024 08:18:34

Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to...

Exploit
  • EPSS 13.62%
  • Veröffentlicht 14.09.2019 16:15:10
  • Zuletzt bearbeitet 21.11.2024 04:30:28

SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.