« List of all CVEs

CVE-2022-1720

Buffer Over-read in function grab_file_name in vim/vim

Published: 5/16/2022 Last updated: 8/3/2024 Reserved: 5/14/2022

Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

CNA assigner: @huntrdev (c09c270a-b464-47c1-9133-acb35b22c19a) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 6.6 Medium CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H

Opam packages affected (1)

conf-vim

Products affected (1)

Product Vendor Version
vim/vim vim 23.0 ap376622

References (30)