vim kayıtları
vim üreticisine ait 254 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 10
- Düzeltme kaydı olan
- %96,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-122 Heap-based Buffer Overflow61
- CWE-416 Use After Free45
- CWE-125 Out-of-bounds Read20
- CWE-476 NULL Pointer Dereference18
- CWE-787 Out-of-bounds Write15
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
254 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2008-2712Kavram kanıtı | Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properlvim · vim · CWE-20 | Kritik9,3 | — | %15,0 | 16 Haz 2008 |
40Planlayın | CVE-2019-12735Kavram kanıtı | getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command ivim · vim · CWE-78 | Yüksek8,6 | — | %19,0 | 5 Haz 2019 |
40Planlayın | CVE-2008-4101Kavram kanıtı | Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell vim · vim · CWE-20 | Kritik9,3 | — | %9,2 | 18 Eyl 2008 |
40Planlayın | CVE-2010-3914İstismar yok | Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local usvim · gvim | Kritik9,3 | — | %9,1 | 3 Kas 2010 |
40Planlayın | CVE-2008-3076Kavram kanıtı | The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filenavim · vim · CWE-78 | Kritik9,3 | — | %9,0 | 21 Şub 2009 |
40Planlayın | CVE-2017-6350İstismar yok | An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validatevim · vim · CWE-190 | Kritik9,8 | — | %3,2 | 27 Şub 2017 |
40Planlayın | CVE-2017-5953İstismar yok | vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overfvim · vim · CWE-190 | Kritik9,8 | — | %2,8 | 10 Şub 2017 |
40Planlayın | CVE-2017-6349İstismar yok | An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate valuvim · vim · CWE-190 | Kritik9,8 | — | %2,7 | 27 Şub 2017 |
40Planlayın | CVE-2022-0318İstismar yok | Heap-based Buffer Overflow in vim/vimvim · vim · CWE-122 | Kritik9,8 | — | %2,0 | 21 Oca 2022 |
39İzleyin | CVE-2022-0572İstismar yok | Heap-based Buffer Overflow in vim/vimvim · vim · CWE-122 | Yüksek7,8 | — | %26,5 | 14 Şub 2022 |
39İzleyin | CVE-2016-1248İstismar yok | vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execuvim · vim · CWE-20 | Yüksek7,8 | — | %25,3 | 23 Kas 2016 |
39İzleyin | CVE-2020-20703İstismar yok | Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.vim · vim · CWE-120 | Kritik9,8 | — | %1,5 | 20 Haz 2023 |
39İzleyin | CVE-2022-3520İstismar yok | Heap-based Buffer Overflow in vim/vimvim · vim · CWE-122 | Kritik9,8 | — | %1,0 | 2 Ara 2022 |
38İzleyin | CVE-2008-3075İstismar yok | The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exvim · vim · CWE-94 | Kritik9,3 | — | %4,3 | 21 Şub 2009 |
38İzleyin | CVE-2008-3074İstismar yok | The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exvim · tar.vim · CWE-78 | Kritik9,3 | — | %3,8 | 21 Şub 2009 |
38İzleyin | CVE-2008-6235İstismar yok | The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a fvim · vim · CWE-78 | Kritik9,3 | — | %3,0 | 21 Şub 2009 |
35İzleyin | CVE-2025-27423İstismar yok | Improper Input Validation in Vimvim · vim · CWE-77 | Yüksek7,1 | — | %22,5 | 3 Mar 2025 |
35İzleyin | CVE-2022-0729İstismar yok | Use of Out-of-range Pointer Offset in vim/vimvim · vim · CWE-823 | Yüksek8,8 | — | %1,6 | 23 Şub 2022 |
34İzleyin | CVE-2026-34714İstismar yok | Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr}vim · vim · CWE-78 | Yüksek8,6 | — | %0,3 | 30 Mar 2026 |
33İzleyin | CVE-2021-3968İstismar yok | Heap-based Buffer Overflow in vim/vimvim · vim · CWE-122 | Yüksek8,0 | — | %2,2 | 19 Kas 2021 |
33İzleyin | CVE-2026-59856İstismar yok | Vim: Arbitrary Code Execution via PHP Omni-Completionvim · vim · CWE-94 | Yüksek8,4 | — | %0,2 | 9 Tem 2026 |
33İzleyin | CVE-2026-51400İstismar yok | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within fivim · vim · CWE-401 | Yüksek8,4 | — | %0,2 | 4 Ağu 2026 |
33İzleyin | CVE-2026-57456İstismar yok | Vim: Arbitrary Code Execution via Python Omni-Completion Docstringsvim · vim · CWE-94 | Yüksek8,4 | — | %0,1 | 25 Haz 2026 |
33İzleyin | CVE-2026-59858İstismar yok | Vim: Arbitrary Code Execution via C Omni-Completionvim · vim · CWE-94 | Yüksek8,4 | — | %0,1 | 9 Tem 2026 |
32İzleyin | CVE-2022-1381İstismar yok | global heap buffer overflow in skip_range in vim/vimvim · vim · CWE-122 | Yüksek7,8 | — | %3,1 | 17 Nis 2022 |
- CVE-2008-271242Planlayın
Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properl
KritikCVSS 9,3Kavram kanıtıEPSS %15vim · vim16 Haz 2008
- CVE-2019-1273540Planlayın
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command i
YüksekCVSS 8,6Kavram kanıtıEPSS %19vim · vim5 Haz 2019
- CVE-2008-410140Planlayın
Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell
KritikCVSS 9,3Kavram kanıtıEPSS %9vim · vim18 Eyl 2008
- CVE-2010-391440Planlayın
Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local us
KritikCVSS 9,3İstismar yokEPSS %9vim · gvim3 Kas 2010
- CVE-2008-307640Planlayın
The Netrw plugin 125 in netrw.vim in Vim 7.2a.10 allows user-assisted attackers to execute arbitrary code via shell metacharacters in filena
KritikCVSS 9,3Kavram kanıtıEPSS %9vim · vim21 Şub 2009
- CVE-2017-635040Planlayın
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate
KritikCVSS 9,8İstismar yokEPSS %3vim · vim27 Şub 2017
- CVE-2017-595340Planlayın
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overf
KritikCVSS 9,8İstismar yokEPSS %3vim · vim10 Şub 2017
- CVE-2017-634940Planlayın
An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate valu
KritikCVSS 9,8İstismar yokEPSS %3vim · vim27 Şub 2017
- CVE-2022-031840Planlayın
Heap-based Buffer Overflow in vim/vim
KritikCVSS 9,8İstismar yokEPSS %2vim · vim21 Oca 2022
- CVE-2022-057239İzleyin
Heap-based Buffer Overflow in vim/vim
YüksekCVSS 7,8İstismar yokEPSS %26vim · vim14 Şub 2022
- CVE-2016-124839İzleyin
vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execu
YüksekCVSS 7,8İstismar yokEPSS %25vim · vim23 Kas 2016
- CVE-2020-2070339İzleyin
Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.
KritikCVSS 9,8İstismar yokEPSS %2vim · vim20 Haz 2023
- CVE-2022-352039İzleyin
Heap-based Buffer Overflow in vim/vim
KritikCVSS 9,8İstismar yokEPSS %1vim · vim2 Ara 2022
- CVE-2008-307538İzleyin
The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (ex
KritikCVSS 9,3İstismar yokEPSS %4vim · vim21 Şub 2009
- CVE-2008-307438İzleyin
The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (ex
KritikCVSS 9,3İstismar yokEPSS %4vim · tar.vim21 Şub 2009
- CVE-2008-623538İzleyin
The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a f
KritikCVSS 9,3İstismar yokEPSS %3vim · vim21 Şub 2009
- CVE-2025-2742335İzleyin
Improper Input Validation in Vim
YüksekCVSS 7,1İstismar yokEPSS %22vim · vim3 Mar 2025
- CVE-2022-072935İzleyin
Use of Out-of-range Pointer Offset in vim/vim
YüksekCVSS 8,8İstismar yokEPSS %2vim · vim23 Şub 2022
- CVE-2026-3471434İzleyin
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr}
YüksekCVSS 8,6İstismar yokEPSS %0vim · vim30 Mar 2026
- CVE-2021-396833İzleyin
Heap-based Buffer Overflow in vim/vim
YüksekCVSS 8,0İstismar yokEPSS %2vim · vim19 Kas 2021
- CVE-2026-5985633İzleyin
Vim: Arbitrary Code Execution via PHP Omni-Completion
YüksekCVSS 8,4İstismar yokEPSS %0vim · vim9 Tem 2026
- CVE-2026-5140033İzleyin
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within fi
YüksekCVSS 8,4İstismar yokEPSS %0vim · vim4 Ağu 2026
- CVE-2026-5745633İzleyin
Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings
YüksekCVSS 8,4İstismar yokEPSS %0vim · vim25 Haz 2026
- CVE-2026-5985833İzleyin
Vim: Arbitrary Code Execution via C Omni-Completion
YüksekCVSS 8,4İstismar yokEPSS %0vim · vim9 Tem 2026
- CVE-2022-138132İzleyin
global heap buffer overflow in skip_range in vim/vim
YüksekCVSS 7,8İstismar yokEPSS %3vim · vim17 Nis 2022