Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-6539 3 Don Ho, Notepad++, Notepad-plus-plus 3 Notepad\+\+, Notepad++, Notepad\+\+ 2026-07-28 4.4 Medium
Notepad++ 8.9.3 contains a format string injection vulnerability in the Find Results panel handler that allows attackers to cause denial of service and information disclosure by crafting a malicious nativeLang.xml language pack file. Attackers can distribute a poisoned language pack through community channels that triggers format string interpretation when a user performs search operations, leading to access violations and potential leakage of stack or register contents.
CVE-2014-9456 1 Don Ho 1 Notepad\+\+ 2025-04-12 N/A
Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Event element in an XML file. NOTE: this issue was originally incorrectly mapped to CVE-2014-1004; see CVE-2014-1004 for more information.