Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-52745 | Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed by the initial `:s` command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue. |
Ubuntu USN |
USN-6557-1 | Vim vulnerabilities |
Thu, 17 Sep 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fedoraproject
Fedoraproject fedora Neovim Neovim neovim Netapp Netapp hci Compute Node |
|
| CPEs | cpe:2.3:a:neovim:neovim:*:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Fedoraproject
Fedoraproject fedora Neovim Neovim neovim Netapp Netapp hci Compute Node |
Tue, 23 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-23T17:19:11.719Z
Reserved: 2023-11-17T19:43:37.554Z
Link: CVE-2023-48706
Updated: 2024-08-02T21:37:54.655Z
Status : Analyzed
Published: 2023-11-22T22:15:08.673
Modified: 2026-09-17T17:59:18.660
Link: CVE-2023-48706
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN