Skip to content
Noroxi

vim records

254 published records for vendor vim.

All records

254 records
  • Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properl

    CriticalCVSS 9.3Proof of conceptEPSS 15%

    vim · vimJun 16, 2008

  • getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command i

    HighCVSS 8.6Proof of conceptEPSS 19%

    vim · vimJun 5, 2019

  • Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell

    CriticalCVSS 9.3Proof of conceptEPSS 9%

    vim · vimSep 18, 2008

  • Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local us

    CriticalCVSS 9.3No exploitEPSS 9%

    vim · gvimNov 3, 2010

  • The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filena

    CriticalCVSS 9.3Proof of conceptEPSS 9%

    vim · vimFeb 21, 2009

  • An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate

    CriticalCVSS 9.8No exploitEPSS 3%

    vim · vimFeb 27, 2017

  • vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overf

    CriticalCVSS 9.8No exploitEPSS 3%

    vim · vimFeb 10, 2017

  • An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate valu

    CriticalCVSS 9.8No exploitEPSS 3%

    vim · vimFeb 27, 2017

  • Heap-based Buffer Overflow in vim/vim

    CriticalCVSS 9.8No exploitEPSS 2%

    vim · vimJan 21, 2022

  • CVE-2022-0572
    39Monitor

    Heap-based Buffer Overflow in vim/vim

    HighCVSS 7.8No exploitEPSS 26%

    vim · vimFeb 14, 2022

  • CVE-2016-1248
    39Monitor

    vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execu

    HighCVSS 7.8No exploitEPSS 25%

    vim · vimNov 23, 2016

  • Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.

    CriticalCVSS 9.8No exploitEPSS 2%

    vim · vimJun 20, 2023

  • CVE-2022-3520
    39Monitor

    Heap-based Buffer Overflow in vim/vim

    CriticalCVSS 9.8No exploitEPSS 1%

    vim · vimDec 2, 2022

  • CVE-2008-3075
    38Monitor

    The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (ex

    CriticalCVSS 9.3No exploitEPSS 4%

    vim · vimFeb 21, 2009

  • CVE-2008-3074
    38Monitor

    The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (ex

    CriticalCVSS 9.3No exploitEPSS 4%

    vim · tar.vimFeb 21, 2009

  • CVE-2008-6235
    38Monitor

    The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a f

    CriticalCVSS 9.3No exploitEPSS 3%

    vim · vimFeb 21, 2009

  • Improper Input Validation in Vim

    HighCVSS 7.1No exploitEPSS 22%

    vim · vimMar 3, 2025

  • CVE-2022-0729
    35Monitor

    Use of Out-of-range Pointer Offset in vim/vim

    HighCVSS 8.8No exploitEPSS 2%

    vim · vimFeb 23, 2022

  • Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr}

    HighCVSS 8.6No exploitEPSS 0%

    vim · vimMar 30, 2026

  • CVE-2021-3968
    33Monitor

    Heap-based Buffer Overflow in vim/vim

    HighCVSS 8.0No exploitEPSS 2%

    vim · vimNov 19, 2021

  • Vim: Arbitrary Code Execution via PHP Omni-Completion

    HighCVSS 8.4No exploitEPSS 0%

    vim · vimJul 9, 2026

  • An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within fi

    HighCVSS 8.4No exploitEPSS 0%

    vim · vimAug 4, 2026

  • Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings

    HighCVSS 8.4No exploitEPSS 0%

    vim · vimJun 25, 2026

  • Vim: Arbitrary Code Execution via C Omni-Completion

    HighCVSS 8.4No exploitEPSS 0%

    vim · vimJul 9, 2026

  • CVE-2022-1381
    32Monitor

    global heap buffer overflow in skip_range in vim/vim

    HighCVSS 7.8No exploitEPSS 3%

    vim · vimApr 17, 2022