Unrated severityNVD Advisory· Published May 14, 2007· Updated Apr 23, 2026
CVE-2007-2666
CVE-2007-2666
Description
Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines. NOTE: this was originally reported as a vulnerability in notepad++.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
12- secunia.com/advisories/25245nvdVendor Advisory
- www.vupen.com/english/advisories/2007/1794nvdVendor Advisory
- www.vupen.com/english/advisories/2007/1867nvdVendor Advisory
- osvdb.org/36007nvd
- scintilla.cvs.sourceforge.net/scintilla/scintilla/src/LexRuby.cxxnvd
- secunia.com/advisories/25327nvd
- www.securityfocus.com/archive/1/468529/100/0/threadednvd
- www.securityfocus.com/archive/1/469348/100/100/threadednvd
- www.securityfocus.com/bid/23961nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/34269nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/34372nvd
- www.exploit-db.com/exploits/3912nvd
News mentions
0No linked articles in our index yet.