Scintilla is a text-editor and syntax-highlighting component widely embedded in development tools and applications, with its vulnerability exposure centered on the single product line. The observed weakness classes—improper restriction of operations within memory bounds and out-of-bounds writes—reflect the parsing and buffer-management demands of a code-rendering library; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Scintilla over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16294HIGH SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file. | Sep 14, 2019 | 7.8 | 41 | NO | YES |
CVE-2007-2666HIGH Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code | May 14, 2007 | 7.6 | 35 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Scintilla.
Media articles that mention a CVE ID that affects a product developed by Scintilla — matched by CVE ID, not by vendor name.