CVE-2026-32249
- EPSS 0.01%
- Veröffentlicht 12.03.2026 19:17:23
- Zuletzt bearbeitet 18.03.2026 11:50:06
Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]), incorrectly emits th...
CVE-2026-28419
- EPSS 0%
- Veröffentlicht 27.02.2026 22:16:25
- Zuletzt bearbeitet 04.03.2026 21:22:05
Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the start of a line, Vim...
CVE-2026-28420
- EPSS 0.01%
- Veröffentlicht 27.02.2026 22:16:25
- Zuletzt bearbeitet 04.03.2026 20:47:23
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. ...
CVE-2026-28421
- EPSS 0.01%
- Veröffentlicht 27.02.2026 22:16:25
- Zuletzt bearbeitet 04.03.2026 20:47:36
Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks wi...
CVE-2026-28422
- EPSS 0.01%
- Veröffentlicht 27.02.2026 22:16:25
- Zuletzt bearbeitet 04.03.2026 20:44:22
Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a very wide terminal. Version 9.2.0078 patches the issu...
CVE-2026-28418
- EPSS 0%
- Veröffentlicht 27.02.2026 21:58:37
- Zuletzt bearbeitet 03.03.2026 17:49:55
Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can be tricked into reading up...
CVE-2026-28417
- EPSS 0.01%
- Veröffentlicht 27.02.2026 21:54:35
- Zuletzt bearbeitet 03.03.2026 17:50:29
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol hand...
CVE-2026-26269
- EPSS 0.04%
- Veröffentlicht 13.02.2026 19:18:41
- Zuletzt bearbeitet 18.02.2026 21:29:03
Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans feature. The...
CVE-2026-25749
- EPSS 0.01%
- Veröffentlicht 06.02.2026 22:43:38
- Zuletzt bearbeitet 20.02.2026 15:45:19
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() funct...
CVE-2025-66476
- EPSS 0.02%
- Veröffentlicht 02.12.2025 21:49:24
- Zuletzt bearbeitet 30.01.2026 18:50:29
Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious executables placed in the current working directory for the current edited file. On Windo...