Перейти к содержимому
Noroxi

Записи vim

254 опубликованных записей вендора vim.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
10
С записью об исправлении
96,5 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

254 записей
  • CVE-2008-2712
    42В плане

    Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properl

    КритическаяCVSS 9,3Proof of conceptEPSS 15 %

    vim · vim16 июн. 2008 г.

  • CVE-2019-12735
    40В плане

    getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command i

    ВысокаяCVSS 8,6Proof of conceptEPSS 19 %

    vim · vim5 июн. 2019 г.

  • CVE-2008-4101
    40В плане

    Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell

    КритическаяCVSS 9,3Proof of conceptEPSS 9 %

    vim · vim18 сент. 2008 г.

  • CVE-2010-3914
    40В плане

    Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local us

    КритическаяCVSS 9,3Эксплойта нетEPSS 9 %

    vim · gvim3 нояб. 2010 г.

  • CVE-2008-3076
    40В плане

    The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filena

    КритическаяCVSS 9,3Proof of conceptEPSS 9 %

    vim · vim21 февр. 2009 г.

  • CVE-2017-6350
    40В плане

    An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    vim · vim27 февр. 2017 г.

  • CVE-2017-5953
    40В плане

    vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overf

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    vim · vim10 февр. 2017 г.

  • CVE-2017-6349
    40В плане

    An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate valu

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    vim · vim27 февр. 2017 г.

  • CVE-2022-0318
    40В плане

    Heap-based Buffer Overflow in vim/vim

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    vim · vim21 янв. 2022 г.

  • CVE-2022-0572
    39Наблюдать

    Heap-based Buffer Overflow in vim/vim

    ВысокаяCVSS 7,8Эксплойта нетEPSS 26 %

    vim · vim14 февр. 2022 г.

  • CVE-2016-1248
    39Наблюдать

    vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execu

    ВысокаяCVSS 7,8Эксплойта нетEPSS 25 %

    vim · vim23 нояб. 2016 г.

  • CVE-2020-20703
    39Наблюдать

    Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    vim · vim20 июн. 2023 г.

  • CVE-2022-3520
    39Наблюдать

    Heap-based Buffer Overflow in vim/vim

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    vim · vim2 дек. 2022 г.

  • CVE-2008-3075
    38Наблюдать

    The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (ex

    КритическаяCVSS 9,3Эксплойта нетEPSS 4 %

    vim · vim21 февр. 2009 г.

  • CVE-2008-3074
    38Наблюдать

    The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (ex

    КритическаяCVSS 9,3Эксплойта нетEPSS 4 %

    vim · tar.vim21 февр. 2009 г.

  • CVE-2008-6235
    38Наблюдать

    The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a f

    КритическаяCVSS 9,3Эксплойта нетEPSS 3 %

    vim · vim21 февр. 2009 г.

  • CVE-2025-27423
    35Наблюдать

    Improper Input Validation in Vim

    ВысокаяCVSS 7,1Эксплойта нетEPSS 22 %

    vim · vim3 мар. 2025 г.

  • CVE-2022-0729
    35Наблюдать

    Use of Out-of-range Pointer Offset in vim/vim

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    vim · vim23 февр. 2022 г.

  • CVE-2026-34714
    34Наблюдать

    Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr}

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    vim · vim30 мар. 2026 г.

  • CVE-2021-3968
    33Наблюдать

    Heap-based Buffer Overflow in vim/vim

    ВысокаяCVSS 8,0Эксплойта нетEPSS 2 %

    vim · vim19 нояб. 2021 г.

  • CVE-2026-59856
    33Наблюдать

    Vim: Arbitrary Code Execution via PHP Omni-Completion

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    vim · vim9 июл. 2026 г.

  • CVE-2026-51400
    33Наблюдать

    An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within fi

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    vim · vim4 авг. 2026 г.

  • CVE-2026-57456
    33Наблюдать

    Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    vim · vim25 июн. 2026 г.

  • CVE-2026-59858
    33Наблюдать

    Vim: Arbitrary Code Execution via C Omni-Completion

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    vim · vim9 июл. 2026 г.

  • CVE-2022-1381
    32Наблюдать

    global heap buffer overflow in skip_range in vim/vim

    ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %

    vim · vim17 апр. 2022 г.