CVE-2026-51400
- EPSS 0.15%
- Veröffentlicht 04.08.2026 00:00:00
- Zuletzt bearbeitet 05.08.2026 18:17:11
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c
CVE-2026-59856
- EPSS 0.22%
- Veröffentlicht 09.07.2026 22:39:01
- Zuletzt bearbeitet 14.07.2026 05:16:19
Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is r...
CVE-2026-59858
- EPSS 0.14%
- Veröffentlicht 09.07.2026 22:37:52
- Zuletzt bearbeitet 14.07.2026 05:16:19
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that ...
CVE-2026-59857
- EPSS 0.11%
- Veröffentlicht 09.07.2026 22:34:54
- Zuletzt bearbeitet 10.07.2026 19:23:21
Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writ...
CVE-2026-55693
- EPSS 0.12%
- Veröffentlicht 25.06.2026 15:34:33
- Zuletzt bearbeitet 26.06.2026 14:17:05
Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded onl...
CVE-2026-55892
- EPSS 0.12%
- Veröffentlicht 25.06.2026 15:32:41
- Zuletzt bearbeitet 26.06.2026 19:16:44
Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded on...
CVE-2026-55895
- EPSS 0.15%
- Veröffentlicht 25.06.2026 15:31:29
- Zuletzt bearbeitet 26.06.2026 05:16:31
Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the brows...
CVE-2026-57451
- EPSS 0.12%
- Veröffentlicht 25.06.2026 15:28:50
- Zuletzt bearbeitet 26.06.2026 04:11:55
Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline after a line's text and returns it as the number of 32-byte textprop_T entries that follow. The only ch...
CVE-2026-57452
- EPSS 0.12%
- Veröffentlicht 25.06.2026 15:27:50
- Zuletzt bearbeitet 26.06.2026 04:12:32
Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05! method (xchacha20poly1305, requires the +sodium feature) whose body is shorter than a single libsodium secretstr...
CVE-2026-57453
- EPSS 0.14%
- Veröffentlicht 25.06.2026 15:26:48
- Zuletzt bearbeitet 26.06.2026 17:16:34
Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries in a zip archive, it builds the PowerShell command...