« List of all CVEs

CVE-2022-1616

Use after free in append_command in vim/vim

Published: 5/7/2022 Last updated: 8/3/2024 Reserved: 5/6/2022

Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

CNA assigner: @huntrdev (c09c270a-b464-47c1-9133-acb35b22c19a) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 7.3 High CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H

Opam packages affected (1)

conf-vim

Products affected (1)

Product Vendor Version
vim/vim vim < 8.3.4

References (24)