CVE-2025-49144
- EPSS 0.62%
- Veröffentlicht 23.06.2025 19:01:16
- Zuletzt bearbeitet 15.04.2026 00:35:42
Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executa...
CVE-2023-47452
- EPSS 0.54%
- Veröffentlicht 30.11.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:30:17
An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.
CVE-2023-6401
- EPSS 0.33%
- Veröffentlicht 30.11.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 08:43:47
A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file dbghelp.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally...
CVE-2023-40166
- EPSS 0.47%
- Veröffentlicht 25.08.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:18:54
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectLanguageFromTextBegining `. The exploitability of this issue is not clear. Potentially, it may be used...
CVE-2023-40164
- EPSS 0.55%
- Veröffentlicht 25.08.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:18:54
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `nsCodingStateMachine::NextStater`. The exploitability of this issue is not clear. Potentially, it may be used to leak i...
CVE-2023-40036
- EPSS 0.43%
- Veröffentlicht 25.08.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:18:34
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to...
CVE-2023-40031
- EPSS 0.49%
- Veröffentlicht 25.08.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:18:33
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are...
CVE-2019-16294
- EPSS 9.83%
- Veröffentlicht 14.09.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 04:30:28
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.