CVE-2022-3037

Executive Summary

CVE-2022-3037 is a use‑after‑free vulnerability in Vim (versions prior to 9.0.0322) that can lead to memory corruption and potentially arbitrary code execution. The flaw occurs when the editor frees a buffer without properly invalidating pointers, allowing an attacker to trigger a crash or execute malicious code via crafted input. The issue is not listed in the CISA KEV database.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2022-08-30T21:15:09.723 - Last Modified: 2026-09-24T15:52:28.627

Original Description: Use After Free in GitHub repository vim/vim prior to 9.0.0322.

"Successful people ask better questions, and as a result, they get better answers."

— Tony Robbins
Source: NVD