« List of all CVEs

CVE-2022-1616

Use after free in append_command in vim/vim

Published: 5/7/2022 Last updated: 11/3/2025 Reserved: 5/6/2022

Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

CNA assigner: @huntrdev (c09c270a-b464-47c1-9133-acb35b22c19a) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 7.3 High CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H

Opam packages affected (1)

conf-vim

Products affected (2)

Product Vendor Version
vim/vim vim n/a
vim/vim vim SDX20M

References (50)