Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44420
HistoryNov 28, 2023 - 8:56 a.m.

Use-After-Free

2023-11-2808:56:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
vim
vulnerability
use-after-free
memory
issue
malicious attackers
crash
control
system

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

31.0%

vim is vulnerable to Use-After-Free. The vulnerability occurs when closing windows due to a memory access issue resulting in malicious attackers being able to crash the application or potentially even gain control of the system.

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

31.0%