Vulnerabilities
Vulnerable Software
Notepad-Plus-Plus:  Security Vulnerabilities
Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.
CVSS Score
6.5
EPSS Score
0.004
Published
2023-01-19
Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.
CVSS Score
7.8
EPSS Score
0.001
Published
2022-09-28
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
CVSS Score
7.8
EPSS Score
0.136
Published
2019-09-14
Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a "Data from Faulting Address controls Code Flow" issue. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands.
CVSS Score
7.8
EPSS Score
0.003
Published
2017-07-05


Contact Us

Shodan ® - All rights reserved