İçeriğe atla
Noroxi

vim kayıtları

vim üreticisine ait 254 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
10
Düzeltme kaydı olan
%96,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

254 kayıt
  • CVE-2008-2712
    42Planlayın

    Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properl

    KritikCVSS 9,3Kavram kanıtıEPSS %15

    vim · vim16 Haz 2008

  • CVE-2019-12735
    40Planlayın

    getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command i

    YüksekCVSS 8,6Kavram kanıtıEPSS %19

    vim · vim5 Haz 2019

  • CVE-2008-4101
    40Planlayın

    Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell

    KritikCVSS 9,3Kavram kanıtıEPSS %9

    vim · vim18 Eyl 2008

  • CVE-2010-3914
    40Planlayın

    Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local us

    KritikCVSS 9,3İstismar yokEPSS %9

    vim · gvim3 Kas 2010

  • CVE-2008-3076
    40Planlayın

    The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filena

    KritikCVSS 9,3Kavram kanıtıEPSS %9

    vim · vim21 Şub 2009

  • CVE-2017-6350
    40Planlayın

    An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate

    KritikCVSS 9,8İstismar yokEPSS %3

    vim · vim27 Şub 2017

  • CVE-2017-5953
    40Planlayın

    vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overf

    KritikCVSS 9,8İstismar yokEPSS %3

    vim · vim10 Şub 2017

  • CVE-2017-6349
    40Planlayın

    An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate valu

    KritikCVSS 9,8İstismar yokEPSS %3

    vim · vim27 Şub 2017

  • CVE-2022-0318
    40Planlayın

    Heap-based Buffer Overflow in vim/vim

    KritikCVSS 9,8İstismar yokEPSS %2

    vim · vim21 Oca 2022

  • CVE-2022-0572
    39İzleyin

    Heap-based Buffer Overflow in vim/vim

    YüksekCVSS 7,8İstismar yokEPSS %26

    vim · vim14 Şub 2022

  • CVE-2016-1248
    39İzleyin

    vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execu

    YüksekCVSS 7,8İstismar yokEPSS %25

    vim · vim23 Kas 2016

  • CVE-2020-20703
    39İzleyin

    Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.

    KritikCVSS 9,8İstismar yokEPSS %2

    vim · vim20 Haz 2023

  • CVE-2022-3520
    39İzleyin

    Heap-based Buffer Overflow in vim/vim

    KritikCVSS 9,8İstismar yokEPSS %1

    vim · vim2 Ara 2022

  • CVE-2008-3075
    38İzleyin

    The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (ex

    KritikCVSS 9,3İstismar yokEPSS %4

    vim · vim21 Şub 2009

  • CVE-2008-3074
    38İzleyin

    The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (ex

    KritikCVSS 9,3İstismar yokEPSS %4

    vim · tar.vim21 Şub 2009

  • CVE-2008-6235
    38İzleyin

    The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a f

    KritikCVSS 9,3İstismar yokEPSS %3

    vim · vim21 Şub 2009

  • CVE-2025-27423
    35İzleyin

    Improper Input Validation in Vim

    YüksekCVSS 7,1İstismar yokEPSS %22

    vim · vim3 Mar 2025

  • CVE-2022-0729
    35İzleyin

    Use of Out-of-range Pointer Offset in vim/vim

    YüksekCVSS 8,8İstismar yokEPSS %2

    vim · vim23 Şub 2022

  • CVE-2026-34714
    34İzleyin

    Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr}

    YüksekCVSS 8,6İstismar yokEPSS %0

    vim · vim30 Mar 2026

  • CVE-2021-3968
    33İzleyin

    Heap-based Buffer Overflow in vim/vim

    YüksekCVSS 8,0İstismar yokEPSS %2

    vim · vim19 Kas 2021

  • CVE-2026-59856
    33İzleyin

    Vim: Arbitrary Code Execution via PHP Omni-Completion

    YüksekCVSS 8,4İstismar yokEPSS %0

    vim · vim9 Tem 2026

  • CVE-2026-51400
    33İzleyin

    An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within fi

    YüksekCVSS 8,4İstismar yokEPSS %0

    vim · vim4 Ağu 2026

  • CVE-2026-57456
    33İzleyin

    Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings

    YüksekCVSS 8,4İstismar yokEPSS %0

    vim · vim25 Haz 2026

  • CVE-2026-59858
    33İzleyin

    Vim: Arbitrary Code Execution via C Omni-Completion

    YüksekCVSS 8,4İstismar yokEPSS %0

    vim · vim9 Tem 2026

  • CVE-2022-1381
    32İzleyin

    global heap buffer overflow in skip_range in vim/vim

    YüksekCVSS 7,8İstismar yokEPSS %3

    vim · vim17 Nis 2022