Vulnerability Description
Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Notepad-Plus-Plus | Notepad\+\+ | <= 8.4.3 |
Related Weaknesses (CWE)
References
- https://github.com/CDACesec/CVE-2022-31901ExploitThird Party Advisory
- https://github.com/CDACesec/CVE-2022-31901ExploitThird Party Advisory
FAQ
What is CVE-2022-31901?
CVE-2022-31901 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Buffer overflow in function Notepad_plus::addHotSpot in Notepad++ v8.4.3 and earlier allows attackers to crash the application via two crafted files.
How severe is CVE-2022-31901?
CVE-2022-31901 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31901?
Check the references section above for vendor advisories and patch information. Affected products include: Notepad-Plus-Plus Notepad\+\+.