Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flos-freeware
Flos-freeware notepad2 |
|
| CPEs | cpe:2.3:a:flos-freeware:notepad2:4.2.25:*:*:*:*:*:*:* | |
| Vendors & Products |
Flos-freeware
Flos-freeware notepad2 |
Mon, 23 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Flos Freeware
Flos Freeware notepad2 |
|
| Vendors & Products |
Flos Freeware
Flos Freeware notepad2 |
Sun, 22 Mar 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipulation can lead to uncontrolled search path. The attack is restricted to local execution. The attack requires a high level of complexity. The exploitability is said to be difficult. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Flos Freeware Notepad2 TextShaping.dll uncontrolled search path | |
| Weaknesses | CWE-426 CWE-427 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-23T16:39:39.426Z
Reserved: 2026-03-21T16:44:04.131Z
Link: CVE-2026-4546
Updated: 2026-03-23T16:15:21.646Z
Status : Analyzed
Published: 2026-03-22T14:16:34.383
Modified: 2026-04-30T14:25:11.943
Link: CVE-2026-4546
No data.
OpenCVE Enrichment
Updated: 2026-03-25T14:46:29Z