CVE-2025-22134 is a heap-buffer overflow vulnerability in Vim, affecting NetApp and Vim products, specifically when using the :all command while visual mode is active. This local vulnerability has a medium severity CVSS score of 5.5, requiring user interaction to trigger, and can lead to high availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE. The issue has been patched in Vim version 9.1.1003.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.10.4CPE matchmatch criteria | cpe:2.3:a:neovim:neovim:*:*:*:*:*:*:*:* | ||
<= 9.1.1003CPE matchmatch criteria | cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025HP ThinPro 8.1 SP7 Security Updates
Jun 3, 2025heap-buffer-overflow with visual mode in Vim < 9.1.1003
Jan 14, 2025vim: heap-buffer-overflow with visual mode in Vim < 9.1.1003
Jan 13, 2025