{"api_version":"1","generated_at":"2026-07-23T13:22:04+00:00","cve":"CVE-2023-0909","urls":{"html":"https://cve.report/CVE-2023-0909","api":"https://cve.report/api/cve/CVE-2023-0909.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-0909","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-0909"},"summary":{"title":"CVE-2023-0909","description":"A vulnerability, which was classified as problematic, was found in cxasm notepad-- 1.22. This affects an unknown part of the component Directory Comparison Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The associated identifier of this vulnerability is VDB-221475.","state":"PUBLIC","assigner":"cna@vuldb.com","published_at":"2023-02-18 09:15:00","updated_at":"2023-11-07 04:01:00"},"problem_types":["CWE-404"],"metrics":[],"references":[{"url":"https://vuldb.com/?ctiid.221475","name":"https://vuldb.com/?ctiid.221475","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://vuldb.com/?id.221475","name":"https://vuldb.com/?id.221475","refsource":"MISC","tags":[],"title":"Login required","mime":"text/html","httpstatus":"401","archivestatus":"404"},{"url":"https://gitee.com/cxasm/notepad--/issues/I6C80Z","name":"https://gitee.com/cxasm/notepad--/issues/I6C80Z","refsource":"MISC","tags":[],"title":"[bug] 非注册版本，使用目录比较，导致NDD崩溃，且无crash文件 · Issue #I6C80Z · 爬山虎/ndd - Gitee.com","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-0909","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-0909","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"909","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"notepad--_project","cpe5":"notepad--","cpe6":"1.22","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-0909","ASSIGNER":"cna@vuldb.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A vulnerability, which was classified as problematic, was found in cxasm notepad-- 1.22. This affects an unknown part of the component Directory Comparison Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The associated identifier of this vulnerability is VDB-221475."},{"lang":"deu","value":"Es wurde eine problematische Schwachstelle in cxasm notepad-- 1.22 gefunden. Es betrifft eine unbekannte Funktion der Komponente Directory Comparison Handler. Dank Manipulation mit unbekannten Daten kann eine denial of service-Schwachstelle ausgenutzt werden. Der Angriff muss lokal erfolgen."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-404 Denial of Service","cweId":"CWE-404"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"cxasm","product":{"product_data":[{"product_name":"notepad--","version":{"version_data":[{"version_affected":"=","version_value":"1.22"}]}}]}}]}},"references":{"reference_data":[{"url":"https://vuldb.com/?id.221475","refsource":"MISC","name":"https://vuldb.com/?id.221475"},{"url":"https://vuldb.com/?ctiid.221475","refsource":"MISC","name":"https://vuldb.com/?ctiid.221475"},{"url":"https://gitee.com/cxasm/notepad--/issues/I6C80Z","refsource":"MISC","name":"https://gitee.com/cxasm/notepad--/issues/I6C80Z"}]},"credits":[{"lang":"en","value":"VulDB Gitee Analyzer"}],"impact":{"cvss":[{"version":"3.1","baseScore":3.3,"vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseSeverity":"LOW"},{"version":"3.0","baseScore":3.3,"vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","baseSeverity":"LOW"},{"version":"2.0","baseScore":1.7,"vectorString":"AV:L/AC:L/Au:S/C:N/I:N/A:P"}]}},"nvd":{"publishedDate":"2023-02-18 09:15:00","lastModifiedDate":"2023-11-07 04:01:00","problem_types":["CWE-404"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.8,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:notepad--_project:notepad--:1.22:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}