packetstormsecurity.com
http://packetstormsecurity.com/files/154706/Notepad-Code-Execution-Denial-Of-Service.html CVE-2019-16294
HIGH
Notepad++ < 7.7 (x64) - Denial of Service
Record summary
CVE-2019-16294 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBNotepad++ < 7.7 (x64) - Denial of ServiceExploitDB exploitby Bogdan KurinnoyNot analyzed1 file
References
5github.com
https://github.com/bi7s/CVE/tree/master/CVE-2019-16294 notepad-plus-plus.org
https://notepad-plus-plus.org/download/v7.7.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-16294 scintilla.org
https://www.scintilla.org/ScintillaHistory.html