Buffer over-read in Notepad++ - #VU137484
Published: September 8, 2023 / Updated: July 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in nsCodingStateMachine::NextState when parsing a crafted file during file open. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.
User interaction is required to open a crafted file.