CVE-2022-1886 is a high-severity heap-based buffer overflow vulnerability affecting Vim prior to version 8.2, including various Fedora Project distributions of Vim. This flaw carries a CVSS score of 7.8, indicating a high potential for impact, as it could lead to complete compromise of confidentiality, integrity, and availability if successfully exploited. Exploitation requires user interaction and local access, but the attack complexity is low. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.2.5016CPE matchmatch criteria | cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
< 8.2CPE match | cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024HP ThinPro 8.1 SP 2 Security Updates
Apr 12, 2024CVE-2022-1886
Jun 14, 2022vim: heap-based buffer overflow in function utf_head_off
May 26, 2022Heap-based Buffer Overflow in vim/vim
May 10, 2022