CVE-2023-1175
Executive Summary
Vim versions prior to 9.0.1378 incorrectly calculate buffer size for certain operations, allowing an attacker to overflow a buffer and corrupt memory. This flaw can lead to arbitrary code execution or denial‑of‑service when processing crafted input. The vulnerability is not yet listed in CISA KEV but is publicly disclosed and mitigated by updating to 9.0.1378 or later.
Authoritative CVE Metadata - CVSS Base Score: 6.6 (MEDIUM) - Published: 2023-03-04T16:15:09.533 - Last Modified: 2026-09-18T15:37:59.490
Original Description: Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
"There are two primary choices in life: to accept conditions as they exist, or accept responsibility for changing them."
— Denis Waitley
Source: NVD