CVE-2023-2426Medium· 5.3▾ SunlitUse of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.
fedora = 37fedora = 38macos = 11.7.9macos = 12.6.8neovim >= 0.7.0, < 0.10.0vim < 9.0.1499Upgrade past the affected range:
neovim 0.10.0vim 9.0.1499Connected by shared product, vendor, weakness, or advisory.
CVE-2023-0433High· 7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
CVE-2023-0288High· 7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
CVE-2022-3256High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.0530.
CVE-2022-3134High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.0389.
CVE-2022-3037High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.0322.
CVE-2023-0049High· 7.8Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.