vim records
254 published records for vendor vim.
All records
254 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2008-2712Proof of concept | Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properlvim · vim · CWE-20 | Critical9.3 | — | 15.0% | Jun 16, 2008 |
40Plan | CVE-2019-12735Proof of concept | getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command ivim · vim · CWE-78 | High8.6 | — | 19.0% | Jun 5, 2019 |
40Plan | CVE-2008-4101Proof of concept | Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell vim · vim · CWE-20 | Critical9.3 | — | 9.2% | Sep 18, 2008 |
40Plan | CVE-2010-3914No exploit | Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local usvim · gvim | Critical9.3 | — | 9.1% | Nov 3, 2010 |
40Plan | CVE-2008-3076Proof of concept | The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenavim · vim · CWE-78 | Critical9.3 | — | 9.0% | Feb 21, 2009 |
40Plan | CVE-2017-6350No exploit | An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validatevim · vim · CWE-190 | Critical9.8 | — | 3.2% | Feb 27, 2017 |
40Plan | CVE-2017-5953No exploit | vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overfvim · vim · CWE-190 | Critical9.8 | — | 2.8% | Feb 10, 2017 |
40Plan | CVE-2017-6349No exploit | An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate valuvim · vim · CWE-190 | Critical9.8 | — | 2.7% | Feb 27, 2017 |
40Plan | CVE-2022-0318No exploit | Heap-based Buffer Overflow in vim/vimvim · vim · CWE-122 | Critical9.8 | — | 2.0% | Jan 21, 2022 |
39Monitor | CVE-2022-0572No exploit | Heap-based Buffer Overflow in vim/vimvim · vim · CWE-122 | High7.8 | — | 26.5% | Feb 14, 2022 |
39Monitor | CVE-2016-1248No exploit | vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execuvim · vim · CWE-20 | High7.8 | — | 25.3% | Nov 23, 2016 |
39Monitor | CVE-2020-20703No exploit | Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.vim · vim · CWE-120 | Critical9.8 | — | 1.5% | Jun 20, 2023 |
39Monitor | CVE-2022-3520No exploit | Heap-based Buffer Overflow in vim/vimvim · vim · CWE-122 | Critical9.8 | — | 1.0% | Dec 2, 2022 |
38Monitor | CVE-2008-3075No exploit | The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exvim · vim · CWE-94 | Critical9.3 | — | 4.3% | Feb 21, 2009 |
38Monitor | CVE-2008-3074No exploit | The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exvim · tar.vim · CWE-78 | Critical9.3 | — | 3.8% | Feb 21, 2009 |
38Monitor | CVE-2008-6235No exploit | The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a fvim · vim · CWE-78 | Critical9.3 | — | 3.0% | Feb 21, 2009 |
35Monitor | CVE-2025-27423No exploit | Improper Input Validation in Vimvim · vim · CWE-77 | High7.1 | — | 22.5% | Mar 3, 2025 |
35Monitor | CVE-2022-0729No exploit | Use of Out-of-range Pointer Offset in vim/vimvim · vim · CWE-823 | High8.8 | — | 1.6% | Feb 23, 2022 |
34Monitor | CVE-2026-34714No exploit | Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr}vim · vim · CWE-78 | High8.6 | — | 0.3% | Mar 30, 2026 |
33Monitor | CVE-2021-3968No exploit | Heap-based Buffer Overflow in vim/vimvim · vim · CWE-122 | High8.0 | — | 2.2% | Nov 19, 2021 |
33Monitor | CVE-2026-59856No exploit | Vim: Arbitrary Code Execution via PHP Omni-Completionvim · vim · CWE-94 | High8.4 | — | 0.2% | Jul 9, 2026 |
33Monitor | CVE-2026-51400No exploit | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within fivim · vim · CWE-401 | High8.4 | — | 0.2% | Aug 4, 2026 |
33Monitor | CVE-2026-57456No exploit | Vim: Arbitrary Code Execution via Python Omni-Completion Docstringsvim · vim · CWE-94 | High8.4 | — | 0.1% | Jun 25, 2026 |
33Monitor | CVE-2026-59858No exploit | Vim: Arbitrary Code Execution via C Omni-Completionvim · vim · CWE-94 | High8.4 | — | 0.1% | Jul 9, 2026 |
32Monitor | CVE-2022-1381No exploit | global heap buffer overflow in skip_range in vim/vimvim · vim · CWE-122 | High7.8 | — | 3.1% | Apr 17, 2022 |
- CVE-2008-271242Plan
Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properl
CriticalCVSS 9.3Proof of conceptEPSS 15%vim · vimJun 16, 2008
- CVE-2019-1273540Plan
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command i
HighCVSS 8.6Proof of conceptEPSS 19%vim · vimJun 5, 2019
- CVE-2008-410140Plan
Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell
CriticalCVSS 9.3Proof of conceptEPSS 9%vim · vimSep 18, 2008
- CVE-2010-391440Plan
Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local us
CriticalCVSS 9.3No exploitEPSS 9%vim · gvimNov 3, 2010
- CVE-2008-307640Plan
The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filena
CriticalCVSS 9.3Proof of conceptEPSS 9%vim · vimFeb 21, 2009
- CVE-2017-635040Plan
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate
CriticalCVSS 9.8No exploitEPSS 3%vim · vimFeb 27, 2017
- CVE-2017-595340Plan
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overf
CriticalCVSS 9.8No exploitEPSS 3%vim · vimFeb 10, 2017
- CVE-2017-634940Plan
An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate valu
CriticalCVSS 9.8No exploitEPSS 3%vim · vimFeb 27, 2017
- CVE-2022-031840Plan
Heap-based Buffer Overflow in vim/vim
CriticalCVSS 9.8No exploitEPSS 2%vim · vimJan 21, 2022
- CVE-2022-057239Monitor
Heap-based Buffer Overflow in vim/vim
HighCVSS 7.8No exploitEPSS 26%vim · vimFeb 14, 2022
- CVE-2016-124839Monitor
vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execu
HighCVSS 7.8No exploitEPSS 25%vim · vimNov 23, 2016
- CVE-2020-2070339Monitor
Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.
CriticalCVSS 9.8No exploitEPSS 2%vim · vimJun 20, 2023
- CVE-2022-352039Monitor
Heap-based Buffer Overflow in vim/vim
CriticalCVSS 9.8No exploitEPSS 1%vim · vimDec 2, 2022
- CVE-2008-307538Monitor
The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (ex
CriticalCVSS 9.3No exploitEPSS 4%vim · vimFeb 21, 2009
- CVE-2008-307438Monitor
The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (ex
CriticalCVSS 9.3No exploitEPSS 4%vim · tar.vimFeb 21, 2009
- CVE-2008-623538Monitor
The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a f
CriticalCVSS 9.3No exploitEPSS 3%vim · vimFeb 21, 2009
- CVE-2025-2742335Monitor
Improper Input Validation in Vim
HighCVSS 7.1No exploitEPSS 22%vim · vimMar 3, 2025
- CVE-2022-072935Monitor
Use of Out-of-range Pointer Offset in vim/vim
HighCVSS 8.8No exploitEPSS 2%vim · vimFeb 23, 2022
- CVE-2026-3471434Monitor
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr}
HighCVSS 8.6No exploitEPSS 0%vim · vimMar 30, 2026
- CVE-2021-396833Monitor
Heap-based Buffer Overflow in vim/vim
HighCVSS 8.0No exploitEPSS 2%vim · vimNov 19, 2021
- CVE-2026-5985633Monitor
Vim: Arbitrary Code Execution via PHP Omni-Completion
HighCVSS 8.4No exploitEPSS 0%vim · vimJul 9, 2026
- CVE-2026-5140033Monitor
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within fi
HighCVSS 8.4No exploitEPSS 0%vim · vimAug 4, 2026
- CVE-2026-5745633Monitor
Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings
HighCVSS 8.4No exploitEPSS 0%vim · vimJun 25, 2026
- CVE-2026-5985833Monitor
Vim: Arbitrary Code Execution via C Omni-Completion
HighCVSS 8.4No exploitEPSS 0%vim · vimJul 9, 2026
- CVE-2022-138132Monitor
global heap buffer overflow in skip_range in vim/vim
HighCVSS 7.8No exploitEPSS 3%vim · vimApr 17, 2022