Home
Packages
Report
Policy
Login
Signup
« List of all CVEs
CVE-2023-5344
Heap-based Buffer Overflow in vim/vim
Published:
10/2/2023
Last updated:
6/18/2025
Reserved:
10/2/2023
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
CNA assigner:
@huntrdev (c09c270a-b464-47c1-9133-acb35b22c19a)
Requested by:
n/a
Metrics
Version
Score
Severity
Vector String
3.0
4
Medium
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Opam packages affected (1)
conf-vim
Products affected (1)
Product
Vendor
Version
vim/vim
vim
QCA6174
References (22)
https://huntr.dev/bounties/530cb762-899e-48d7-b50e-dad09eb775bf
https://github.com/vim/vim/commit/3bd7fa12e146c6051490d048a4acbfba974eeb04
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4W665GQBN6S6ZDMYWVF4X7KMFI7AQKJL/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZOXBUJLJ5VSPN3YXWN7XZA4JDYKNE7GZ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XPT7NMYJRLBPIALGSE24UWTY6F774GZW/
https://support.apple.com/kb/HT214038
https://support.apple.com/kb/HT214036
https://support.apple.com/kb/HT214037
http://seclists.org/fulldisclosure/2023/Dec/9
http://seclists.org/fulldisclosure/2023/Dec/10
http://seclists.org/fulldisclosure/2023/Dec/11
https://huntr.dev/bounties/530cb762-899e-48d7-b50e-dad09eb775bf
https://github.com/vim/vim/commit/3bd7fa12e146c6051490d048a4acbfba974eeb04
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4W665GQBN6S6ZDMYWVF4X7KMFI7AQKJL/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZOXBUJLJ5VSPN3YXWN7XZA4JDYKNE7GZ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XPT7NMYJRLBPIALGSE24UWTY6F774GZW/
https://support.apple.com/kb/HT214038
https://support.apple.com/kb/HT214036
https://support.apple.com/kb/HT214037
http://seclists.org/fulldisclosure/2023/Dec/9
http://seclists.org/fulldisclosure/2023/Dec/10
http://seclists.org/fulldisclosure/2023/Dec/11