605
VMScore

CVE-2022-1720

Published: 20/06/2022 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer Over-read in function grab_file_name in GitHub repository vim/vim before 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

vim vim

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 35

fedoraproject fedora 36

apple macos

Vendor Advisories

Debian Bug report logs - #1015984 vim: CVE-2022-1942 CVE-2022-1968 CVE-2022-2000 CVE-2022-2124 CVE-2022-2125 CVE-2022-2126 CVE-2022-2129 CVE-2022-2285 CVE-2022-2288 CVE-2022-2304 CVE-2022-2207 CVE-2022-1616 CVE-2022-1619 CVE-2022-1621 CVE-2022-1720 CVE-2022-1785 CVE-2022-1851 CVE-2022-1897 CVE-2022-1898 Package: src:vim; Maintainer for sr ...
Use after free in append_command in GitHub repository vim/vim prior to 824895 This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution (CVE-2022-1616) Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 824899 This vulnerabilities ...
Use after free in append_command in GitHub repository vim/vim prior to 824895 This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution (CVE-2022-1616) Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 824899 This vulnerabilities ...
A heap buffer over-read vulnerability was found in Vim's grab_file_name() function of the src/findfilec file This flaw occurs because the function reads after the NULL terminates the line with "gf" in Visual block mode This flaw allows an attacker to trick a user into opening a specially crafted file, triggering a heap buffer over-read vulnerabi ...