CVE-2020-37040
Severity CVSS v4.0:
HIGH
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
30/01/2026
Last modified:
30/01/2026
Description
Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious file name with Unicode characters. Attackers can trigger the vulnerability by pasting a specially crafted payload into the file name field during project creation, potentially executing system commands like calc.exe.
Impact
Base Score 4.0
8.40
Severity 4.0
HIGH
Base Score 3.x
8.40
Severity 3.x
HIGH



