CVE-2018-20786

HIGH

Leonerd Libvterm < 0\+bzr726 - NULL Pointer Dereference

Title source: rule

Description

libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, state.c, and vterm.c.

Scores

CVSS v3 7.5
EPSS 0.0032
EPSS Percentile 54.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Classification

CWE
CWE-476
Status published

Affected Products (1)

leonerd/libvterm < 0\+bzr726

Timeline

Published Feb 24, 2019
Tracked Since Feb 18, 2026