CVE-2026-57454
- EPSS 0.12%
- Veröffentlicht 25.06.2026 15:24:54
- Zuletzt bearbeitet 26.06.2026 19:16:45
Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a virtual-text property whose offset and length point outside the line's property data. When Vim restores or displays such a line it ...
CVE-2026-57455
- EPSS 0.12%
- Veröffentlicht 25.06.2026 15:22:37
- Zuletzt bearbeitet 26.06.2026 04:23:21
Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loo...
CVE-2026-57456
- EPSS 0.15%
- Veröffentlicht 25.06.2026 15:16:16
- Zuletzt bearbeitet 26.06.2026 05:16:31
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer wi...
CVE-2026-52860
- EPSS 0.22%
- Veröffentlicht 11.06.2026 18:33:45
- Zuletzt bearbeitet 15.07.2026 01:16:22
Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. Python...
CVE-2026-52859
- EPSS 0.3%
- Veröffentlicht 11.06.2026 18:33:09
- Zuletzt bearbeitet 15.06.2026 13:12:47
Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cel...
CVE-2026-52858
- EPSS 0.2%
- Veröffentlicht 11.06.2026 18:32:32
- Zuletzt bearbeitet 15.06.2026 13:32:35
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python interpre...
CVE-2026-47162
- EPSS 0.25%
- Veröffentlicht 11.06.2026 18:32:14
- Zuletzt bearbeitet 19.08.2026 12:18:27
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directo...
CVE-2026-47167
- EPSS 0.14%
- Veröffentlicht 11.06.2026 18:31:44
- Zuletzt bearbeitet 15.06.2026 13:32:14
Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Step-definition patte...
- EPSS 0.55%
- Veröffentlicht 15.05.2026 14:57:31
- Zuletzt bearbeitet 19.05.2026 12:27:28
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip ...
CVE-2026-45130
- EPSS 0.25%
- Veröffentlicht 08.05.2026 22:42:35
- Zuletzt bearbeitet 24.07.2026 20:10:00
Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 encoding active. An attacker-controlled length field i...