← Vulnerability feed

Vulnerability record · CVE-2024-41965 · published 1 August 2024

CVE-2024-41965: Netapp hci compute node use after free vulnerability

NNetapp · Hci Compute Node

Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However, when setting the buffer name to Unnamed, Vim will falsely free a pointer twice, leading to a double-free and possibly later to a heap-use-after-free, which can lead to a crash. The issue has been fixed as of Vim patch v9.1.0648.

4.2 CVSS 3.1 Medium EPSS 0.33% · top 76.3% CWE-416 · Use after freeCWE-415 · Double free
4.2CVSS 3.1 base score
0.33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
3References
17 Sep 2026Last modified by NVD

Description

Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However, when setting the buffer name to Unnamed, Vim will falsely free a pointer twice, leading to a double-free and possibly later to a heap-use-after-free, which can lead to a crash. The issue has been fixed as of Vim patch v9.1.0648.

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-41965 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2019-13272Linux kernel ptrace credential mishandling allows local root escalationThe Linux kernel before 5.1.17 mishandles credential recording in ptrace_link (kernel/ptrace.c) when a process creates a ptrace relationship, and als…KEVEPSS 52%analysed9.8CVE-2024-56171Xmlsoft libxml2 use after free vulnerabilitylibxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. …EPSS 1.2%9.8CVE-2020-20703Vim classic buffer overflow vulnerabilityBuffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.EPSS 1.5%9.8CVE-2022-3520Vim heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.EPSS 1.0%9.8CVE-2022-37434Zlib out-of-bounds write vulnerabilityzlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only appl…EPSS 19%9.8CVE-2022-0318Vim heap-based buffer overflow vulnerabilityHeap-based Buffer Overflow in vim/vim prior to 8.2.EPSS 2.0%9.8CVE-2019-17006Siemens ruggedcom rox mx5000 firmware improper input validation vulnerabilityIn Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling th…EPSS 3.6%9.8CVE-2019-18805Linux kernel integer overflow vulnerabilityAn issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in t…EPSS 3.4%

Source: NIST National Vulnerability Database (record CVE-2024-41965), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.