CVE-2022-3705 is a high-severity use-after-free vulnerability in Vim's autocmd Handler, specifically within the qf_update_buffer function in quickfix.c. This flaw affects products like Debian, FedoraProject, NetApp, and Vim itself, and can be exploited remotely. Successful exploitation could lead to high impact on confidentiality, integrity, and availability due to its network attack vector and high impact scores. While the vulnerability has a high CVSS score of 7.5, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion. Users are advised to upgrade to Vim version 9.0.0805 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.0.0805CPE matchmatch criteria | cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.