CVE-2026-28419
- EPSS 0.17%
- Veröffentlicht 27.02.2026 22:16:25
- Zuletzt bearbeitet 04.03.2026 21:22:05
Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the start of a line, Vim...
CVE-2026-28420
- EPSS 0.18%
- Veröffentlicht 27.02.2026 22:16:25
- Zuletzt bearbeitet 04.03.2026 20:47:23
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. ...
CVE-2026-28421
- EPSS 0.18%
- Veröffentlicht 27.02.2026 22:16:25
- Zuletzt bearbeitet 04.03.2026 20:47:36
Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks wi...
CVE-2026-28422
- EPSS 0.14%
- Veröffentlicht 27.02.2026 22:16:25
- Zuletzt bearbeitet 04.03.2026 20:44:22
Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a very wide terminal. Version 9.2.0078 patches the issu...
CVE-2026-28418
- EPSS 0.22%
- Veröffentlicht 27.02.2026 21:58:37
- Zuletzt bearbeitet 03.03.2026 17:49:55
Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can be tricked into reading up...
CVE-2026-28417
- EPSS 1.16%
- Veröffentlicht 27.02.2026 21:54:35
- Zuletzt bearbeitet 03.03.2026 17:50:29
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol hand...
CVE-2026-26269
- EPSS 0.28%
- Veröffentlicht 13.02.2026 19:18:41
- Zuletzt bearbeitet 18.02.2026 21:29:03
Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans feature. The...
CVE-2026-25749
- EPSS 0.21%
- Veröffentlicht 06.02.2026 22:43:38
- Zuletzt bearbeitet 09.06.2026 18:28:09
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() funct...
CVE-2025-66476
- EPSS 0.44%
- Veröffentlicht 02.12.2025 21:49:24
- Zuletzt bearbeitet 30.01.2026 18:50:29
Vim is an open source, command line text editor. Prior to version 9.1.1947, an uncontrolled search path vulnerability on Windows allows Vim to execute malicious executables placed in the current working directory for the current edited file. On Windo...
CVE-2025-9390
- EPSS 0.27%
- Veröffentlicht 24.08.2025 14:15:32
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in vim up to 9.1.1615. Affected by this vulnerability is the function main of the file src/xxd/xxd.c of the component xxd. The manipulation results in buffer overflow. The attack requires a local approach. The expl...