CVE-2025-9390
- EPSS 0.03%
- Published 24.08.2025 14:15:32
- Last modified 24.09.2025 13:50:57
A security flaw has been discovered in vim up to 9.1.1615. Affected by this vulnerability is the function main of the file src/xxd/xxd.c of the component xxd. The manipulation results in buffer overflow. The attack requires a local approach. The expl...
CVE-2025-9389
- EPSS 0.03%
- Published 24.08.2025 13:15:29
- Last modified 12.09.2025 18:38:34
A vulnerability was identified in vim 9.1.0000. Affected is the function __memmove_avx_unaligned_erms of the file memmove-vec-unaligned-erms.S. The manipulation leads to memory corruption. The attack needs to be performed locally. The exploit is publ...
CVE-2025-55157
- EPSS 0.05%
- Published 11.08.2025 22:54:27
- Last modified 12.08.2025 18:50:20
Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tuples in Vim script, an error during evaluation can trigger a use-after-free in Vim’s internal tuple reference management. Specific...
CVE-2025-55158
- EPSS 0.05%
- Published 11.08.2025 22:54:12
- Last modified 12.08.2025 18:49:05
Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operations, an error during evaluation can trigger a double-free in Vim’s internal typed value (typ...
CVE-2025-53906
- EPSS 0.02%
- Published 15.07.2025 20:52:40
- Last modified 14.08.2025 01:41:11
Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requir...
CVE-2025-53905
- EPSS 0.02%
- Published 15.07.2025 20:48:34
- Last modified 14.08.2025 01:41:04
Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives. Impact is low because this exploit requir...
CVE-2025-29768
- EPSS 0.1%
- Published 13.03.2025 17:15:37
- Last modified 18.08.2025 14:14:27
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange ...
CVE-2025-27423
- EPSS 0.46%
- Published 03.03.2025 17:15:15
- Last modified 18.08.2025 18:20:37
Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. Starting with 9.1.0858, the tar.vim plugin uses the ":read" ex command line t...
CVE-2025-26603
- EPSS 0.04%
- Published 18.02.2025 19:15:29
- Last modified 18.08.2025 18:23:32
Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:disp...
CVE-2025-1215
- EPSS 0.13%
- Published 12.02.2025 19:15:10
- Last modified 13.08.2025 17:28:19
A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the l...