Логотип exploitDog
bind: "CVE-2023-48706"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2023-48706"

Количество 9

Количество 9

ubuntu логотип

CVE-2023-48706

больше 1 года назад

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed by the initial `:s` command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.

CVSS3: 3.6
EPSS: Низкий
redhat логотип

CVE-2023-48706

больше 1 года назад

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed by the initial `:s` command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2023-48706

больше 1 года назад

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed by the initial `:s` command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.

CVSS3: 3.6
EPSS: Низкий
debian логотип

CVE-2023-48706

больше 1 года назад

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-a ...

CVSS3: 3.6
EPSS: Низкий
fstec логотип

BDU:2023-08297

больше 1 года назад

Уязвимость текстового редактора vim, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код

CVSS3: 3.6
EPSS: Низкий
redos логотип

ROS-20240328-16

около 1 года назад

Уязвимость VIM

CVSS3: 3.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:1287-1

около 1 года назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0871-1

больше 1 года назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0783-1

больше 1 года назад

Security update for vim

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-48706

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed by the initial `:s` command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.

CVSS3: 3.6
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-48706

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed by the initial `:s` command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-48706

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed by the initial `:s` command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.

CVSS3: 3.6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-48706

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-a ...

CVSS3: 3.6
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2023-08297

Уязвимость текстового редактора vim, связанная с использованием памяти после её освобождения, позволяющая нарушителю выполнить произвольный код

CVSS3: 3.6
0%
Низкий
больше 1 года назад
redos логотип
ROS-20240328-16

Уязвимость VIM

CVSS3: 3.6
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:1287-1

Security update for vim

около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0871-1

Security update for vim

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0783-1

Security update for vim

больше 1 года назад

Уязвимостей на страницу