<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Notepad++ (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/notepad-plus-plus.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/notepad-plus-plus-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Notepad++ (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:50 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2021-47944 – memono Notepad 4.2 contains a denial of service vulnerability that allows attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47944</guid>
    <pubDate>Sun, 10 May 2026 13:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47944</strong></p>
  <p>memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash on iOS devices.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42214 – Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42214</guid>
    <pubDate>Thu, 07 May 2026 19:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42214</strong></p>
  <p>Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpolates a file's extension directly into a Lua script without sanitization. An attacker can craft a filename whose extension contains Lua code, which executes automatically when the victim opens the file in NotepadNext. Because luaL_openlibs() is called…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32616 – Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32616</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32616</strong></p>
  <p>Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] without validation to construct email verification URLs in the register and resendmail flows. An attacker can manipulate the Host header in the HTTP request, causing the verification link sent to the user's email to point to an attacker-controlled domain. This can lead to account tak…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25866 – MobaXterm versions prior to 26.1 contain an uncontrolled search path element vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25866</guid>
    <pubDate>Mon, 09 Mar 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25866</strong></p>
  <p>MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable path when opening remote files. An attacker can exploit the search path behavior by placing a malicious executable earlier in the search order, resulting in arbitrary code execution in the context of the affected user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25926 – Notepad++ is a free and open-source source code editor. An Unsafe Search Path vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25926</guid>
    <pubDate>Thu, 19 Feb 2026 00:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25926</strong></p>
  <p>Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explorer.exe if an attacker can control the process working directory. Under certain conditions, this could lead to arbitrary code execution in the contex…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20841 – Improper neutralization of special elements used in a command ('command injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20841</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20841</strong></p>
  <p>Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15556 – Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an upd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15556</guid>
    <pubDate>Tue, 03 Feb 2026 01:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15556</strong></p>
  <p>Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23512 – SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23512</guid>
    <pubDate>Wed, 14 Jan 2026 21:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23512</strong></p>
  <p>SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application executes notepad.exe without specifying an absolute path when using the Advanced Options setting. On Windows, this allows execution of a malicious notepad.exe placed in the application's installation directory, leading to a…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56383 – Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the origin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56383</guid>
    <pubDate>Fri, 26 Sep 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56383</strong></p>
  <p>Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivileged users.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49144 – Notepad++ is a free and open-source source code editor. In versions 8.8.1 and pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49144</guid>
    <pubDate>Mon, 23 Jun 2025 19:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49144</strong></p>
  <p>Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malici…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-272</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-39441 – Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Dashboard Notepad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-39441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-39441</guid>
    <pubDate>Thu, 17 Apr 2025 16:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-39441</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Dashboard Notepads dashboard-notepads allows Stored XSS.This issue affects Dashboard Notepads: from n/a through <= 1.2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-47452 – An Untrusted search path vulnerability in notepad++ 6.5 allows local users to ga...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47452</guid>
    <pubDate>Thu, 30 Nov 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-47452</strong></p>
  <p>An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40031 – Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40031</guid>
    <pubDate>Fri, 25 Aug 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40031</strong></p>
  <p>Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing versions of Notepad++.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-34159 – Improper permission control vulnerability in the Notepad app.Successful exploita...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34159</guid>
    <pubDate>Mon, 19 Jun 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-34159</strong></p>
  <p>Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48227 – An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48227</guid>
    <pubDate>Tue, 04 Apr 2023 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48227</strong></p>
  <p>An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows elevation of privileges because it opens Notepad after the installation of AssureID, Identify x64, and Identify x86, aka CORE-7361.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32168 – Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32168</guid>
    <pubDate>Wed, 28 Sep 2022 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32168</strong></p>
  <p>Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-40854 – AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain admini...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40854</guid>
    <pubDate>Thu, 14 Oct 2021 05:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-40854</strong></p>
  <p>AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16294 – SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16294</guid>
    <pubDate>Sat, 14 Sep 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16294</strong></p>
  <p>SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-8803 – Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8803</guid>
    <pubDate>Wed, 05 Jul 2017 20:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-8803</strong></p>
  <p>Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a "Data from Faulting Address controls Code Flow" issue. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-9456 – Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9456</guid>
    <pubDate>Fri, 02 Jan 2015 20:59:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-9456</strong></p>
  <p>Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Event element in an XML file.  NOTE: this issue was originally incorrectly mapped to CVE-2014-1004; see CVE-2014-1004 for more information.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-3436 – The GUP generic update process in Notepad++ before 4.8.1 does not properly verif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3436</guid>
    <pubDate>Fri, 01 Aug 2008 14:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-3436</strong></p>
  <p>The GUP generic update process in Notepad++ before 4.8.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-1210 – Stack-based buffer overflow in the ctags parsing code in Programmer's Notepad be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1210</guid>
    <pubDate>Sat, 08 Mar 2008 00:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-1210</strong></p>
  <p>Stack-based buffer overflow in the ctags parsing code in Programmer's Notepad before 2.0.8.718 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted .c file, when the victim selects the Jump To dialog.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-2666 – Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2666</guid>
    <pubDate>Mon, 14 May 2007 23:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-2666</strong></p>
  <p>Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines.  NOTE: this was originally reported as a vulnerability in notepad++.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-1274 – Classic Planer in AntiVir PersonalEdition Classic 7 does not drop privileges bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-1274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-1274</guid>
    <pubDate>Sun, 19 Mar 2006 11:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-1274</strong></p>
  <p>Classic Planer in AntiVir PersonalEdition Classic 7 does not drop privileges before executing external programs, which allows local users to gain privileges via notepad.exe, which is used to display scan reports.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-1274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-0008 – The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-0008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-0008</guid>
    <pubDate>Tue, 14 Feb 2006 19:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-0008</strong></p>
  <p>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-0008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-2504 – The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-2504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-2504</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-2504</strong></p>
  <p>The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users create new files, which allows local users with physical access to gain privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-2504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-1624 – Carbon Copy 6.0.5257 does not drop system privileges when opening external progr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1624</guid>
    <pubDate>Thu, 21 Oct 2004 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-1624</strong></p>
  <p>Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1624">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
