Severity
7.8HIGHNVD
EPSS
0.1%
top 66.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 30
Latest updateNov 16

Description

heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDvim/vim< 8.2.4647
CVEListV5vim/vim_vimunspecified8.2.4647
Alpinevim/vim< 8.2.4708-r0+11

Also affects: Fedora 34, 35, 36

Patches

🔴Vulnerability Details

4
GHSA
Jenkins JUnit Plugin subject to Cross-site Scripting via URL conversion2022-11-16
GHSA
GHSA-rv49-vpf7-3h48: heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 82022-03-31
OSV
CVE-2022-1160: heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 82022-03-30
CVEList
heap buffer overflow in get_one_sourceline in vim/vim2022-03-30

📋Vendor Advisories

3
Red Hat
vim: heap buffer overflow in get_one_sourceline2022-03-28
Microsoft
heap buffer overflow in get_one_sourceline in vim/vim2022-03-08
Debian
CVE-2022-1160: vim - heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to...2022
CVE-2022-1160 — Heap-based Buffer Overflow in VIM VIM | cvebase