← All CVEs

CVE-2007-2666

high · 7.6

Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines. NOTE: this was originally reported as a vulnerability in notepad++.

7.6
CVSS
15.5%
EPSS (exploit prob.)
97th
EPSS percentile
2007-05-14
Published

AV:N/AC:H/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
notepad++notepad++<= 4.1.1
scintillascintilla1.73

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-2666