CVE-2023-40166
Notepad++ is a free and open-source source code editor. Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in `FileManager::detectLanguageFromTextBegining `. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information. As of time of publication, no known patches are available in existing versions of Notepad++.
- Affected products
- Notepad++
- Notepad-plus-plus Notepad\+\+
- ≤ 8.5.6
- Fix
- Available
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 0.5% (38th percentile)
- Weakness
- CWE-120, CWE-122
- NVD status
- Modified
- Published
- 2023-08-25
CVE-2023-40166 at NVD
No indexed exploits for CVE-2023-40166 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-40166 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.