CVE-2023-4734
Executive Summary
CVE‑2023‑4734 describes an integer overflow/wraparound flaw in Vim’s source code (prior to 9.0.1846) that could allow an attacker to corrupt memory or trigger undefined behavior when processing crafted input. The vulnerability is not yet listed in the CISA KEV database, but users of affected Vim versions should apply the 9.0.1846 patch or later to mitigate potential exploitation, which could lead to arbitrary code execution or denial‑of‑service.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2023-09-02T18:15:17.127 - Last Modified: 2026-09-18T15:39:17.740
Original Description: Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
"He that never changes his opinions, never corrects his mistakes, and will never be wiser on the morrow than he is today."
— Tryon Edwards