High severity7.8NVD Advisory· Published Sep 14, 2019· Updated Jun 17, 2026
CVE-2019-16294
CVE-2019-16294
Description
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:notepad-plus-plus:notepad\+\+:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:notepad-plus-plus:notepad\+\+:*:*:*:*:*:*:*:*range: <7.7
- (no CPE)range: <7.7
- Scintilla/Notepad++description
Patches
Vulnerability mechanics
References
4- github.com/bi7s/CVE/tree/master/CVE-2019-16294nvdExploitThird Party Advisory
- packetstormsecurity.com/files/154706/Notepad-Code-Execution-Denial-Of-Service.htmlnvdThird Party AdvisoryVDB Entry
- notepad-plus-plus.org/download/v7.7.htmlnvdRelease NotesVendor Advisory
- www.scintilla.org/ScintillaHistory.htmlnvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.