rpm package
almalinux/vim-common
pkg:rpm/almalinux/vim-common
Vulnerabilities (51)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-28421 | Med | 5.3 | < 2:8.0.1763-22.el8_10.1 | 2:8.0.1763-22.el8_10.1 | Feb 27, 2026 | Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks within a swap file. Version 9.2. | |
| CVE-2026-28420 | Med | 4.4 | < 2:9.1.083-9.el10_2.20 | 2:9.1.083-9.el10_2.20 | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the iss | |
| CVE-2026-28417 | Med | 4.4 | < 2:8.0.1763-22.el8_10.1 | 2:8.0.1763-22.el8_10.1 | Feb 27, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute | |
| CVE-2026-25749 | Med | 6.6 | < 2:8.0.1763-22.el8_10 | 2:8.0.1763-22.el8_10 | Feb 6, 2026 | Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When process | |
| CVE-2025-53906 | Med | 4.1 | < 2:8.0.1763-21.el8_10 | 2:8.0.1763-21.el8_10 | Jul 15, 2025 | Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. Ho | |
| CVE-2025-53905 | Med | 4.1 | < 2:8.0.1763-21.el8_10 | 2:8.0.1763-21.el8_10 | Jul 15, 2025 | Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives. Impact is low because this exploit requires direct user interaction. Ho | |
| CVE-2023-4752 | Hig | 7.8 | < 2:8.2.2637-22.el9_6 | 2:8.2.2637-22.el9_6 | Sep 4, 2023 | Use After Free in GitHub repository vim/vim prior to 9.0.1858. | |
| CVE-2022-47024 | Hig | 7.8 | < 2:8.2.2637-20.el9_1 | 2:8.2.2637-20.el9_1 | Jan 20, 2023 | A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts. | |
| CVE-2022-1927 | Hig | 7.8 | < 2:8.0.1763-19.el8_6.4 | 2:8.0.1763-19.el8_6.4 | May 29, 2022 | Buffer Over-read in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-1897 | Hig | 7.8 | < 2:8.0.1763-19.el8_6.4 | 2:8.0.1763-19.el8_6.4 | May 27, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-1785 | Hig | 7.8 | < 2:8.0.1763-19.el8_6.4 | 2:8.0.1763-19.el8_6.4 | May 19, 2022 | Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977. | |
| CVE-2022-1629 | Hig | 7.8 | < 2:8.2.2637-16.el9_0.2 | 2:8.2.2637-16.el9_0.2 | May 10, 2022 | Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution | |
| CVE-2022-1621 | Hig | 7.8 | < 2:8.2.2637-16.el9_0.2 | 2:8.2.2637-16.el9_0.2 | May 10, 2022 | Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution | |
| CVE-2022-1420 | Med | 5.5 | < 2:8.2.2637-16.el9_0.2 | 2:8.2.2637-16.el9_0.2 | Apr 21, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774. | |
| CVE-2022-1154 | Hig | 7.8 | < 2:8.0.1763-16.el8_5.13 | 2:8.0.1763-16.el8_5.13 | Mar 30, 2022 | Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646. | |
| CVE-2022-0943 | Hig | 7.8 | < 2:8.2.2637-16.el9_0.2 | 2:8.2.2637-16.el9_0.2 | Mar 14, 2022 | Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563. | |
| CVE-2022-0554 | Hig | 7.8 | < 2:8.2.2637-16.el9_0.2 | 2:8.2.2637-16.el9_0.2 | Feb 10, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0413 | Hig | 7.8 | < 2:8.0.1763-16.el8_5.12 | 2:8.0.1763-16.el8_5.12 | Jan 30, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0392 | Hig | 7.8 | < 2:8.0.1763-16.el8_5.12 | 2:8.0.1763-16.el8_5.12 | Jan 28, 2022 | Heap-based Buffer Overflow in GitHub repository vim prior to 8.2. | |
| CVE-2022-0361 | Hig | 7.8 | < 2:8.0.1763-16.el8_5.12 | 2:8.0.1763-16.el8_5.12 | Jan 26, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. |
- affected < 2:8.0.1763-22.el8_10.1fixed 2:8.0.1763-22.el8_10.1
Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks within a swap file. Version 9.2.
- affected < 2:9.1.083-9.el10_2.20fixed 2:9.1.083-9.el10_2.20
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from Unicode supplementary planes. Version 9.2.0076 fixes the iss
- affected < 2:8.0.1763-22.el8_10.1fixed 2:8.0.1763-22.el8_10.1
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute
- affected < 2:8.0.1763-22.el8_10fixed 2:8.0.1763-22.el8_10
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When process
- affected < 2:8.0.1763-21.el8_10fixed 2:8.0.1763-21.el8_10
Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. Ho
- affected < 2:8.0.1763-21.el8_10fixed 2:8.0.1763-21.el8_10
Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives. Impact is low because this exploit requires direct user interaction. Ho
- affected < 2:8.2.2637-22.el9_6fixed 2:8.2.2637-22.el9_6
Use After Free in GitHub repository vim/vim prior to 9.0.1858.
- affected < 2:8.2.2637-20.el9_1fixed 2:8.2.2637-20.el9_1
A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts.
- affected < 2:8.0.1763-19.el8_6.4fixed 2:8.0.1763-19.el8_6.4
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
- affected < 2:8.0.1763-19.el8_6.4fixed 2:8.0.1763-19.el8_6.4
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
- affected < 2:8.0.1763-19.el8_6.4fixed 2:8.0.1763-19.el8_6.4
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.
- affected < 2:8.2.2637-16.el9_0.2fixed 2:8.2.2637-16.el9_0.2
Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution
- affected < 2:8.2.2637-16.el9_0.2fixed 2:8.2.2637-16.el9_0.2
Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
- affected < 2:8.2.2637-16.el9_0.2fixed 2:8.2.2637-16.el9_0.2
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
- affected < 2:8.0.1763-16.el8_5.13fixed 2:8.0.1763-16.el8_5.13
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
- affected < 2:8.2.2637-16.el9_0.2fixed 2:8.2.2637-16.el9_0.2
Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
- affected < 2:8.2.2637-16.el9_0.2fixed 2:8.2.2637-16.el9_0.2
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
- affected < 2:8.0.1763-16.el8_5.12fixed 2:8.0.1763-16.el8_5.12
Use After Free in GitHub repository vim/vim prior to 8.2.
- affected < 2:8.0.1763-16.el8_5.12fixed 2:8.0.1763-16.el8_5.12
Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
- affected < 2:8.0.1763-16.el8_5.12fixed 2:8.0.1763-16.el8_5.12
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Page 2 of 3