« List of all CVEs

CVE-2022-4141

Heap-based Buffer Overflow in vim/vim

Published: 11/25/2022 Last updated: 4/14/2025 Reserved: 11/25/2022

Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

CNA assigner: @huntrdev (c09c270a-b464-47c1-9133-acb35b22c19a) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 7.3 High CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Opam packages affected (1)

conf-vim

Products affected (1)

Product Vendor Version
vim/vim vim 24.0 ap383821

References (12)