CVE-2022-3134High· 7.8▾ TwilightUse After Free in GitHub repository vim/vim prior to 9.0.0389.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
Use After Free in GitHub repository vim/vim prior to 9.0.0389.
neovim >= 0.5.0, < 0.9.0vim < 9.0.0389debian_linux = 10.0debian_linux = 11.0Upgrade past the affected range:
neovim 0.9.0vim 9.0.0389Connected by shared product, vendor, weakness, or advisory.
CVE-2022-3256High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.0530.
CVE-2022-3591High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.0789.
CVE-2022-3297High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.0579.
CVE-2022-4141High· 7.8Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
CVE-2022-3324High· 7.8Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
CVE-2023-0049High· 7.8Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.