CVE-2023-0433High· 7.8▾ TwilightHeap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.6%
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
macos < 11.7.5macos >= 12.0.0, < 12.6.4macos >= 13.0, < 13.3fedora = 36fedora = 37neovim >= 0.1.0, < 0.8.3vim < 9.0.1225Upgrade past the affected range:
macos 13.3neovim 0.8.3vim 9.0.1225Connected by shared product, vendor, weakness, or advisory.
CVE-2023-0288High· 7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
CVE-2023-0049High· 7.8Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
CVE-2022-4141High· 7.8Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
CVE-2023-4738High· 7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
CVE-2023-1170Medium· 6.6Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
CVE-2023-4751High· 7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.