CVE-2024-41965Medium· 4.2▾ SunlitVim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.3%
Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However, when setting the buffer name to Unnamed, Vim will falsely free a pointer twice, leading to a double-free and possibly later to a heap-use-after-free, which can lead to a crash. The issue has been fixed as of Vim patch v9.1.0648.
hci_compute_nodeneovim >= 0.10.0, < 0.10.2vim < 9.1.0648Upgrade past the affected range:
neovim 0.10.2vim 9.1.0648Connected by shared product, vendor, weakness, or advisory.
CVE-2023-5535High· 7.8Use After Free in GitHub repository vim/vim prior to v9.0.2010.
CVE-2023-4752High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.1858.
CVE-2023-48706Low· 3.6Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability
CVE-2023-4750High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.1857.
CVE-2023-4733High· 7.8Use After Free in GitHub repository vim/vim prior to 9.0.1840.
CVE-2023-4738High· 7.8Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.