cbcvebase.
CVE-2025-24014
published 2025-01-20

CVE-2025-24014: Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a…

PriorityP424medium5.5CVSS 3.1
AVLACHPRLUIRSUCLILAH
EPSS
0.26%
17.6th percentile
Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by feeding some binary characters to Vim. The function that handles the scrolling however may be triggering a redraw, which will access the ScreenLines pointer, even so this variable hasn't been allocated (since there is no screen). This vulnerability is fixed in 9.1.1043.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianvim< vim 2:9.1.1113-1 (forky)vim 2:9.1.1113-1 (forky)
vimvim< 9.1.10439.1.1043
vimvim>= 0 < 2:9.1.1113-12:9.1.1113-1
vimvim>= 0 < 2:9.1.1113-12:9.1.1113-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H
osv5.5MEDIUM
vendor_debian4.2LOW
vendor_redhat4.2MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.