CVE-2023-48706Low· 3.6▾ SunlitVim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that t…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 19.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
0.4% → 0.5%
Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a :s command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive :s call causes free-ing of memory which may later then be accessed by the initial :s command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.
fedora = 38fedora = 39hci_compute_nodeneovim <= 0.9.5vim < 9.0.2121Upgrade past the affected range:
vim 9.0.2121Connected by shared product, vendor, weakness, or advisory.
CVE-2023-46246Medium· 4.0Vim is an improved version of the good old UNIX editor Vi
CVE-2024-41965Medium· 4.2Vim is an open source command line text editor
CVE-2023-5535High· 7.8Use After Free in GitHub repository vim/vim prior to v9.0.2010.
CVE-2023-4752High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.1858.
CVE-2023-4750High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.1857.
CVE-2023-4733High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.1840.