<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Notepad++</title>
  <link>https://cvedaily.com/pages/tags/notepad-plus-plus.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/notepad-plus-plus.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Notepad++</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:50 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2021-47944 – memono Notepad 4.2 contains a denial of service vulnerability that allows attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-47944</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-47944</guid>
    <pubDate>Sun, 10 May 2026 13:16:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-47944</strong></p>
  <p>memono Notepad 4.2 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character buffers into note fields. Attackers can generate a payload containing 350000 repeated characters and paste it twice into a new note to trigger an application crash on iOS devices.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-789</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-47944">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-42214 – Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42214</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42214</guid>
    <pubDate>Thu, 07 May 2026 19:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42214</strong></p>
  <p>Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpolates a file's extension directly into a Lua script without sanitization. An attacker can craft a filename whose extension contains Lua code, which executes automatically when the victim opens the file in NotepadNext. Because luaL_openlibs() is called…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42214">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-6539 – Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Res...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-6539</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-6539</guid>
    <pubDate>Thu, 30 Apr 2026 21:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-6539</strong></p>
  <p>Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that triggers format string interpretation when a user performs search operations, leadi…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-134</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-6539">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-5525 – A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-5525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-5525</guid>
    <pubDate>Fri, 10 Apr 2026 08:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-5525</strong></p>
  <p>A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trailing backslash, the application appends a backslash and null terminator without proper bounds checking, resulting in a stack buffer overflow and application crash (STATUS_STACK_BUFFER_OVERRUN).</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-5525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-34401 – XML Notepad is a Windows program that provides a simple intuitive User Interface...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-34401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-34401</guid>
    <pubDate>Tue, 31 Mar 2026 22:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-34401</strong></p>
  <p>XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. There is a well known attack related to malicious DTD files where an attacker to craft a malicious XML file that loads a DTD that causes X…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32616 – Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the appl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32616</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32616</guid>
    <pubDate>Mon, 16 Mar 2026 14:19:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32616</strong></p>
  <p>Pigeon is a message board/notepad/social system/blog. Prior to 1.0.201, the application uses $_SERVER['HTTP_HOST'] without validation to construct email verification URLs in the register and resendmail flows. An attacker can manipulate the Host header in the HTTP request, causing the verification link sent to the user's email to point to an attacker-controlled domain. This can lead to account tak…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32616">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25866 – MobaXterm versions prior to 26.1 contain an uncontrolled search path element vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25866</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25866</guid>
    <pubDate>Mon, 09 Mar 2026 16:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25866</strong></p>
  <p>MobaXterm versions prior to 26.1 contain an uncontrolled search path element vulnerability. The application calls WinExec to execute Notepad++ without a fully qualified executable path when opening remote files. An attacker can exploit the search path behavior by placing a malicious executable earlier in the search order, resulting in arbitrary code execution in the context of the affected user.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-428</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25866">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25926 – Notepad++ is a free and open-source source code editor. An Unsafe Search Path vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25926</guid>
    <pubDate>Thu, 19 Feb 2026 00:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25926</strong></p>
  <p>Notepad++ is a free and open-source source code editor. An Unsafe Search Path vulnerability (CWE-426) exists in versions prior to 8.9.2 when launching Windows Explorer without an absolute executable path. This may allow execution of a malicious explorer.exe if an attacker can control the process working directory. Under certain conditions, this could lead to arbitrary code execution in the contex…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20841 – Improper neutralization of special elements used in a command ('command injectio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20841</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20841</guid>
    <pubDate>Tue, 10 Feb 2026 18:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20841</strong></p>
  <p>Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute code locally.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20841">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-15556 – Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an upd...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15556</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15556</guid>
    <pubDate>Tue, 03 Feb 2026 01:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-15556</strong></p>
  <p>Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the updater to download and execute an attacker-controlled installer, resulting in arbitrary code execution with the privileges…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-494</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15556">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23512 – SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23512</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23512</guid>
    <pubDate>Wed, 14 Jan 2026 21:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23512</strong></p>
  <p>SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, there is a Untrusted Search Path vulnerability when Advanced Options setting is trigger. The application executes notepad.exe without specifying an absolute path when using the Advanced Options setting. On Windows, this allows execution of a malicious notepad.exe placed in the application's installation directory, leading to a…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-426</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23512">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68966 – Permission control vulnerability in the Notepad module.
Impact: Successful explo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68966</guid>
    <pubDate>Wed, 14 Jan 2026 03:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68966</strong></p>
  <p>Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68965 – Permission control vulnerability in the Notepad module.
Impact: Successful explo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68965</guid>
    <pubDate>Wed, 14 Jan 2026 03:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68965</strong></p>
  <p>Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-64311 – Permission control vulnerability in the Notepad module.
Impact: Successful explo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64311</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64311</guid>
    <pubDate>Fri, 28 Nov 2025 03:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-64311</strong></p>
  <p>Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64311">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56383 – Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the origin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56383</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56383</guid>
    <pubDate>Fri, 26 Sep 2025 18:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56383</strong></p>
  <p>Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivileged users.</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56383">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57927 – Cross-Site Request Forgery (CSRF) vulnerability in Stephanie Leary Dashboard Not...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57927</guid>
    <pubDate>Mon, 22 Sep 2025 19:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57927</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in Stephanie Leary Dashboard Notepad dashboard-notepad allows Cross Site Request Forgery.This issue affects Dashboard Notepad: from n/a through <= 1.42.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-49144 – Notepad++ is a free and open-source source code editor. In versions 8.8.1 and pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49144</guid>
    <pubDate>Mon, 23 Jun 2025 19:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-49144</strong></p>
  <p>Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malici…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-272</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-39441 – Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Dashboard Notepad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-39441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-39441</guid>
    <pubDate>Thu, 17 Apr 2025 16:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-39441</strong></p>
  <p>Cross-Site Request Forgery (CSRF) vulnerability in swedish boy Dashboard Notepads dashboard-notepads allows Stored XSS.This issue affects Dashboard Notepads: from n/a through <= 1.2.1.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-39441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-42036 – Access permission verification vulnerability in the Notepad module
Impact: Succe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-42036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-42036</guid>
    <pubDate>Thu, 08 Aug 2024 10:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-42036</strong></p>
  <p>Access permission verification vulnerability in the Notepad module Impact: Successful exploitation of this vulnerability may affect service confidentiality.</p>
  <p><strong>CVSS:</strong> 2.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-42036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-47452 – An Untrusted search path vulnerability in notepad++ 6.5 allows local users to ga...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47452</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47452</guid>
    <pubDate>Thu, 30 Nov 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-47452</strong></p>
  <p>An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47452">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-6401 – A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-6401</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-6401</guid>
    <pubDate>Thu, 30 Nov 2023 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-6401</strong></p>
  <p>A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file dbghelp.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The identifier VDB-246421 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-6401">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40166 – Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40166</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40166</guid>
    <pubDate>Fri, 25 Aug 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40166</strong></p>
  <p>Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectLanguageFromTextBegining `. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40166">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40164 – Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40164</guid>
    <pubDate>Fri, 25 Aug 2023 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40164</strong></p>
  <p>Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `nsCodingStateMachine::NextStater`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-40036 – Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40036</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40036</guid>
    <pubDate>Fri, 25 Aug 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-40036</strong></p>
  <p>Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40036">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-40031 – Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-40031</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-40031</guid>
    <pubDate>Fri, 25 Aug 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-40031</strong></p>
  <p>Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in `Utf8_16_Read::convert`. This issue may lead to arbitrary code execution. As of time of publication, no known patches are available in existing versions of Notepad++.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-40031">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-34159 – Improper permission control vulnerability in the Notepad app.Successful exploita...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34159</guid>
    <pubDate>Mon, 19 Jun 2023 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-34159</strong></p>
  <p>Improper permission control vulnerability in the Notepad app.Successful exploitation of the vulnerability may lead to privilege escalation, which affects availability and confidentiality.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-48227 – An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows ele...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-48227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-48227</guid>
    <pubDate>Tue, 04 Apr 2023 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-48227</strong></p>
  <p>An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows elevation of privileges because it opens Notepad after the installation of AssureID, Identify x64, and Identify x86, aka CORE-7361.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-48227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-0909 – A vulnerability, which was classified as problematic, was found in cxasm notepad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-0909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-0909</guid>
    <pubDate>Sat, 18 Feb 2023 09:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-0909</strong></p>
  <p>A vulnerability, which was classified as problematic, was found in cxasm notepad-- 1.22. This affects an unknown part of the component Directory Comparison Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The associated identifier of this vulnerability is VDB-221475.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-404</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-0909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31902 – Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31902</guid>
    <pubDate>Wed, 01 Feb 2023 02:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31902</strong></p>
  <p>Notepad++ v8.4.1 was discovered to contain a stack overflow via the component Finder::add().</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-31901 – Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and ear...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31901</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31901</guid>
    <pubDate>Thu, 19 Jan 2023 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-31901</strong></p>
  <p>Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31901">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-32168 – Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an att...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-32168</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-32168</guid>
    <pubDate>Wed, 28 Sep 2022 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-32168</strong></p>
  <p>Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-427</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-32168">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-40854 – AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain admini...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-40854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-40854</guid>
    <pubDate>Thu, 14 Oct 2021 05:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-40854</strong></p>
  <p>AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-40854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-16294 – SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-16294</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-16294</guid>
    <pubDate>Sat, 14 Sep 2019 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-16294</strong></p>
  <p>SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-16294">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-2878 – Vulnerability in the PeopleSoft Enterprise HCM Shared Components component of Or...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-2878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-2878</guid>
    <pubDate>Thu, 19 Apr 2018 02:29:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-2878</strong></p>
  <p>Vulnerability in the PeopleSoft Enterprise HCM Shared Components component of Oracle PeopleSoft Products (subcomponent: Notepad). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Shared Components. Successful attacks require human interaction from a person other than…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-2878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-8803 – Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8803</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8803</guid>
    <pubDate>Wed, 05 Jul 2017 20:29:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-8803</strong></p>
  <p>Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a "Data from Faulting Address controls Code Flow" issue. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8803">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-2423 – Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-2423</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-2423</guid>
    <pubDate>Sat, 15 Aug 2015 00:59:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-2423</strong></p>
  <p>Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Exce…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-2423">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2014-9456 – Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-9456</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-9456</guid>
    <pubDate>Fri, 02 Jan 2015 20:59:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2014-9456</strong></p>
  <p>Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Event element in an XML file.  NOTE: this issue was originally incorrectly mapped to CVE-2014-1004; see CVE-2014-1004 for more information.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-9456">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2008-3436 – The GUP generic update process in Notepad++ before 4.8.1 does not properly verif...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-3436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-3436</guid>
    <pubDate>Fri, 01 Aug 2008 14:41:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2008-3436</strong></p>
  <p>The GUP generic update process in Notepad++ before 4.8.1 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-3436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2008-1210 – Stack-based buffer overflow in the ctags parsing code in Programmer's Notepad be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2008-1210</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2008-1210</guid>
    <pubDate>Sat, 08 Mar 2008 00:44:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2008-1210</strong></p>
  <p>Stack-based buffer overflow in the ctags parsing code in Programmer's Notepad before 2.0.8.718 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted .c file, when the victim selects the Jump To dialog.  NOTE: some of these details are obtained from third party information.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2008-1210">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2007-5145 – Multiple buffer overflows in system DLL files in Microsoft Windows XP, as used b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-5145</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-5145</guid>
    <pubDate>Mon, 01 Oct 2007 05:17:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2007-5145</strong></p>
  <p>Multiple buffer overflows in system DLL files in Microsoft Windows XP, as used by Microsoft Windows Explorer (explorer.exe) 6.00.2900.2180, Don Ho Notepad++, unspecified Adobe Macromedia applications, and other programs, allow user-assisted remote attackers to cause a denial of service (application crash) via long strings in the (1) author, (2) title, (3) subject, and (4) comment Properties field…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-5145">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2007-2666 – Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2007-2666</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2007-2666</guid>
    <pubDate>Mon, 14 May 2007 23:19:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2007-2666</strong></p>
  <p>Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines.  NOTE: this was originally reported as a vulnerability in notepad++.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2007-2666">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-5702 – Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL us...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-5702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-5702</guid>
    <pubDate>Sat, 04 Nov 2006 01:07:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-5702</strong></p>
  <p>Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6) tiki-directory_add_site.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-forums.php, (10) tiki-view_forum.php, (11…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-5702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-1274 – Classic Planer in AntiVir PersonalEdition Classic 7 does not drop privileges bef...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-1274</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-1274</guid>
    <pubDate>Sun, 19 Mar 2006 11:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-1274</strong></p>
  <p>Classic Planer in AntiVir PersonalEdition Classic 7 does not drop privileges before executing external programs, which allows local users to gain privileges via notepad.exe, which is used to display scan reports.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-1274">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2006-0008 – The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-0008</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-0008</guid>
    <pubDate>Tue, 14 Feb 2006 19:06:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2006-0008</strong></p>
  <p>The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-0008">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2006-0442 – Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinB...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2006-0442</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2006-0442</guid>
    <pubDate>Thu, 26 Jan 2006 22:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2006-0442</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script or HTML via the (1) notepad parameter in a notepad action and (2) signature parameter in an editsig action. NOTE: These are different attack vectors, and probably a different vulnerability, than CVE-2006-0218 and CVE-2006-0219.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2006-0442">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2005-4192 – Multiple cross-site scripting (XSS) vulnerabilities in templates/notepads/notepa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-4192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-4192</guid>
    <pubDate>Tue, 13 Dec 2005 11:03:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2005-4192</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in templates/notepads/notepads.inc in Horde Mnemo Note Manager H3 before 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) the notepad's name or (2) description, when creating a new notepad.</p>
  <p><strong>CVSS:</strong> 3.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-4192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2005-2430 – Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-2430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-2430</guid>
    <pubDate>Wed, 03 Aug 2005 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2005-2430</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_id or (2) group_id parameter to forum.php, (3) project_task_id parameter to task.php, (4) id parameter to detail.php, (5) the text field on the search page, (6) group_id parameter to qrs.php, (7) form, (8) rows, (9) cols or (10) wrap parameter to notepa…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-2430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-2504 – The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-2504</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-2504</guid>
    <pubDate>Fri, 31 Dec 2004 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-2504</strong></p>
  <p>The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users create new files, which allows local users with physical access to gain privileges.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-2504">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2004-1624 – Carbon Copy 6.0.5257 does not drop system privileges when opening external progr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1624</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1624</guid>
    <pubDate>Thu, 21 Oct 2004 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2004-1624</strong></p>
  <p>Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe).</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1624">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
