CVE-2022-4141
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the subst
CVSS
7.8
High
EPSS
0.4%
p35
KEV
—
Exploit Today
11
0-100
Published: Nov 25, 2022 · Last modified: Sep 24, 2026 · CWE-122 · CWE-787
0.4%EPSS · 30 days0.4%
2026-08-272026-09-24
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
- github.comhttps://github.com/vim/vim/commit/cc762a48d42b579fb7bdec2c614636b830342dd5
- huntr.devhttps://huntr.dev/bounties/20ece512-c600-45ac-8a84-d0931e05541f
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2023/06/msg00015.html
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AZ3JMSUCR6Y7626RDWQ2HNSUFIQOJ33G/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6ZNKVN4GICORTVFKVCM4MSOXCYWNHUC/
- security.gentoo.orghttps://security.gentoo.org/glsa/202305-16
- github.comhttps://github.com/vim/vim/commit/cc762a48d42b579fb7bdec2c614636b830342dd5
- huntr.devhttps://huntr.dev/bounties/20ece512-c600-45ac-8a84-d0931e05541f
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2023/06/msg00015.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2025/03/msg00023.html
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AZ3JMSUCR6Y7626RDWQ2HNSUFIQOJ33G/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6ZNKVN4GICORTVFKVCM4MSOXCYWNHUC/
- security.gentoo.orghttps://security.gentoo.org/glsa/202305-16
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-871185.7 MED—
———The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, potentially disrupting authentication state or causing the affected process to terminate and the device to restart, resulting in a temporary denial of service.20hCVE-2026-883907.7 HIG—
——0An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASSERT builds. The out-of-bounds write corrupts the adjacent tokenValue pointer, resulting in memory corruption and potentially causing application crashes or denial of service.20hCVE-2026-967466.5 MED—
——0An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the end of a heap buffer. This may cause the application using the driver to terminate unexpectedly.20hCVE-2026-134678.1 HIG—
——0Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections.
This issue affects Trusted Firmware: through socfpga_v2.14.0.22hCVE-2026-971857.8 HIG2.3%
——1A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to load a malicious preset file, potentially causing a crash or enabling arbitrary code execution.21hCVE-2026-97152—21.5%
——6Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport, due to an unchecked copy of the Sec-WebSocket-Version header, through snprintf.20h