CVE-2023-4738
Executive Summary
Heap-based buffer overflow in Vim (v9.0.1848 and earlier) allows attackers to corrupt memory, potentially leading to arbitrary code execution or denial of service. The vulnerability is not yet listed in CISA KEV, but mitigations include updating to v9.0.1848 or later, applying patches, or disabling vulnerable features. Users should verify their Vim version and apply security updates promptly.
Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2023-09-02T20:15:07.413 - Last Modified: 2026-09-18T15:39:32.580
Original Description: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
"The industrial landscape is already littered with remains of once successful companies that could not adapt their strategic vision to altered conditions of competition."
— Abernathy