6.6
CVSSv3

CVE-2022-0213

Published: 14/01/2022 Updated: 09/11/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.6 | Impact Score: 4.7 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

It exists that Vim was incorrectly handling window exchanging operations when in Visual mode, which could result in an out-of-bounds read. An attacker could possibly use this issue to expose sensitive information. (CVE-2022-0319)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vim vim

debian debian linux 9.0

debian debian linux 10.0

Vendor Advisories

Several security issues were fixed in Vim ...
It was found that vim was vulnerable to use-after-free flaw in the way it was treating allocated lines in user functions A specially crafted file could crash the vim process or possibly lead to other undefined behaviors (CVE-2022-0156) It was found that vim was vulnerable to a 1 byte heap based out of bounds read flaw in the `compile_get_env()` f ...
It was found that vim was vulnerable to use-after-free flaw in the way it was treating allocated lines in user functions A specially crafted file could crash the vim process or possibly lead to other undefined behaviors (CVE-2022-0156) It was found that vim was vulnerable to a 1 byte heap based out of bounds read flaw in the `compile_get_env()` f ...
vim is vulnerable to Heap-based Buffer Overflow ...
A flaw was found in vim The vulnerability occurs due to not checking the length for the NameBuff function, which can lead to a heap buffer overflow This flaw allows an attacker to input a specially crafted file, leading to a crash or code execution (CVE-2022-0213) A heap based out-of-bounds write flaw was found in vim's opsc This flaw allows ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Re: 3 new CVE's in vim <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Alan Coopersmith &lt;alancoopersmith () o ...