🛡️ CVE-2022-0156
5.5
CVSS Score
0 Low4 Medium7 High9 Critical10
Description
vim is vulnerable to Use After Free
Details
Severity
MEDIUM
CVSS Score
5.5
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CWE
CWE-416
Public Exploit
⚠️ Yes
Source
NVD
Published
2022-01-10
Updated
2026-06-08
Modified
2024-11-21
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| fedora | — | — |
| macos | 11.0 | 11.6.8 |
| vim | — | 8.2.4040 |
References
Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2022/Jul/13
Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2022/Mar/29
Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2022/01/15/1
Patch, Third Party Advisory https://github.com/vim/vim/commit/9f1a39a5d1cd7989ada2d1cb32f97d84360e050f
Exploit, Patch, Third Party Advisory https://huntr.dev/bounties/47dded34-3767-4725-8c7c-9dcb68c70b36
Third Party Advisory https://security.gentoo.org/glsa/202208-32
Release Notes, Third Party Advisory https://support.apple.com/kb/HT213183
Third Party Advisory https://support.apple.com/kb/HT213344
Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2022/Jul/13
Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2022/Mar/29
Mailing List, Third Party Advisory http://www.openwall.com/lists/oss-security/2022/01/15/1
Patch, Third Party Advisory https://github.com/vim/vim/commit/9f1a39a5d1cd7989ada2d1cb32f97d84360e050f
Exploit, Patch, Third Party Advisory https://huntr.dev/bounties/47dded34-3767-4725-8c7c-9dcb68c70b36
Third Party Advisory https://security.gentoo.org/glsa/202208-32
Release Notes, Third Party Advisory https://support.apple.com/kb/HT213183
Third Party Advisory https://support.apple.com/kb/HT213344
Similar Threats
- High CVE-2022-0096
- High CVE-2022-0100
- Critical CVE-2022-0097
- High CVE-2022-0102
- High CVE-2022-0098
Site Security Check
Concerned your site may already be targeted?
BotEraser analyzes incoming traffic patterns and helps identify bot behavior consistent with known exploit attempts.
Check My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.