CVE-2022-4141 is a heap-based buffer overflow vulnerability affecting Vim versions 9.0.0946 and below, including specific Fedora packages. An unauthenticated attacker could exploit this by tricking a user into opening a specially crafted file and executing a CTRL-W gf command, leading to high impact on confidentiality, integrity, and availability. With a CVSS score of 7.8 (High), this vulnerability is considered serious, though it currently lacks public exploit code, Metasploit modules, or evidence of active exploitation. Community discussion and media coverage are minimal, suggesting low current awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0.0946CPE matchmatch criteria | cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
< 9.0.0947CPE match | cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.