Vulnerabilities > CVE-2019-16294 - Out-of-bounds Write vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- http://packetstormsecurity.com/files/154706/Notepad-Code-Execution-Denial-Of-Service.html
- http://packetstormsecurity.com/files/154706/Notepad-Code-Execution-Denial-Of-Service.html
- https://github.com/bi7s/CVE/tree/master/CVE-2019-16294
- https://github.com/bi7s/CVE/tree/master/CVE-2019-16294
- https://notepad-plus-plus.org/download/v7.7.html
- https://notepad-plus-plus.org/download/v7.7.html
- https://www.scintilla.org/ScintillaHistory.html
- https://www.scintilla.org/ScintillaHistory.html