CVE-2023-40036
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to global buffer read overflow in `CharDistributionAnalysis::HandleOneChar`. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.
- Affected products
- Notepad++
- Notepad-plus-plus Notepad\+\+
- ≤ 8.5.6
- Fix
- Available
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 0.4% (35th percentile)
- Weakness
- CWE-120
- NVD status
- Modified
- Published
- 2023-08-25
CVE-2023-40036 at NVD
No indexed exploits for CVE-2023-40036 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-40036 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.