rpm package
almalinux/vim-minimal
pkg:rpm/almalinux/vim-minimal
Vulnerabilities (51)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-73078 | Hig | — | < 2:9.1.083-9.el10_2.20 | 2:9.1.083-9.el10_2.20 | Aug 11, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into exec | |
| CVE-2026-73077 | Hig | — | < 2:9.1.083-9.el10_2.20 | 2:9.1.083-9.el10_2.20 | Aug 11, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating sh | |
| CVE-2026-73076 | Hig | — | < 2:9.1.083-9.el10_2.20 | 2:9.1.083-9.el10_2.20 | Aug 11, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record e | |
| CVE-2026-73072 | Hig | — | < 2:9.1.083-9.el10_2.20 | 2:9.1.083-9.el10_2.20 | Aug 11, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping li | |
| CVE-2026-59858 | Hig | 7.8 | < 2:8.2.2637-26.el9_8.13 | 2:8.2.2637-26.el9_8.13 | Jul 9, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Becau | |
| CVE-2026-59857 | Med | 5.5 | < 2:9.1.083-9.el10_2.20 | 2:9.1.083-9.el10_2.20 | Jul 9, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < M | |
| CVE-2026-59856 | Hig | 7.8 | < 2:8.2.2637-26.el9_8.13 | 2:8.2.2637-26.el9_8.13 | Jul 9, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without e | |
| CVE-2026-57456 | Hig | 7.8 | < 2:8.2.2637-26.el9_8.13 | 2:8.2.2637-26.el9_8.13 | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populatin | |
| CVE-2026-57455 | Hig | 7.8 | < 2:8.2.2637-26.el9_8.13 | 2:8.2.2637-26.el9_8.13 | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri | |
| CVE-2026-55892 | Med | 5.5 | < 2:9.1.083-9.el10_2.20 | 2:9.1.083-9.el10_2.20 | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itsel | |
| CVE-2026-55693 | Hig | 7.8 | < 2:8.2.2637-26.el9_8.13 | 2:8.2.2637-26.el9_8.13 | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself | |
| CVE-2026-52859 | Hig | 8.2 | < 2:9.1.083-9.el10_2.20 | 2:9.1.083-9.el10_2.20 | Jun 11, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no uppe | |
| CVE-2026-52858 | Hig | 7.8 | < 2:9.1.083-9.el10_2.7 | 2:9.1.083-9.el10_2.7 | Jun 11, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python interpreter) executes the import and f | |
| CVE-2026-47167 | Med | 5.3 | < 2:9.1.083-9.el10_2.7 | 2:9.1.083-9.el10_2.7 | Jun 11, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Step-definition patterns read from .rb files under | |
| CVE-2026-47162 | Hig | 8.8 | < 2:9.1.083-9.el10_2.7 | 2:9.1.083-9.el10_2.7 | Jun 11, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~ | |
| CVE-2026-46483 | Low | 3.6 | < 2:9.1.083-9.el10_2.7 | 2:9.1.083-9.el10_2.7 | May 15, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape( | |
| CVE-2026-41411 | Med | 6.6 | < 2:8.2.2637-26.el9_8.6 | 2:8.2.2637-26.el9_8.6 | Apr 24, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcar | |
| CVE-2026-35177 | Med | 4.1 | < 2:9.1.083-9.el10_2.3 | 2:9.1.083-9.el10_2.3 | Apr 6, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in | |
| CVE-2026-34982 | Hig | 8.2 | < 2:8.0.1763-22.el8_10.3 | 2:8.0.1763-22.el8_10.3 | Apr 6, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a | |
| CVE-2026-33412 | Med | 5.6 | < 2:8.0.1763-22.el8_10.1 | 2:8.0.1763-22.el8_10.1 | Mar 24, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary sh |
- affected < 2:9.1.083-9.el10_2.20fixed 2:9.1.083-9.el10_2.20
Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into exec
- affected < 2:9.1.083-9.el10_2.20fixed 2:9.1.083-9.el10_2.20
Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating sh
- affected < 2:9.1.083-9.el10_2.20fixed 2:9.1.083-9.el10_2.20
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record e
- affected < 2:9.1.083-9.el10_2.20fixed 2:9.1.083-9.el10_2.20
Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping li
- affected < 2:8.2.2637-26.el9_8.13fixed 2:8.2.2637-26.el9_8.13
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Becau
- affected < 2:9.1.083-9.el10_2.20fixed 2:9.1.083-9.el10_2.20
Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < M
- affected < 2:8.2.2637-26.el9_8.13fixed 2:8.2.2637-26.el9_8.13
Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without e
- affected < 2:8.2.2637-26.el9_8.13fixed 2:8.2.2637-26.el9_8.13
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populatin
- affected < 2:8.2.2637-26.el9_8.13fixed 2:8.2.2637-26.el9_8.13
Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte map into a caller-owned result buffer. Its copy loop advances the output index ri
- affected < 2:9.1.083-9.el10_2.20fixed 2:9.1.083-9.el10_2.20
Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itsel
- affected < 2:8.2.2637-26.el9_8.13fixed 2:8.2.2637-26.el9_8.13
Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself
- affected < 2:9.1.083-9.el10_2.20fixed 2:9.1.083-9.el10_2.20
Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snapshot is taken. For each screen cell it walks the cell's chars[] array with no uppe
- affected < 2:9.1.083-9.el10_2.7fixed 2:9.1.083-9.el10_2.7
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pythoncomplete.vim for builds with the +python interpreter) executes the import and f
- affected < 2:9.1.083-9.el10_2.7fixed 2:9.1.083-9.el10_2.7
Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on Vim builds with +ruby support. Step-definition patterns read from .rb files under
- affected < 2:9.1.083-9.el10_2.7fixed 2:9.1.083-9.el10_2.7
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file ~
- affected < 2:9.1.083-9.el10_2.7fixed 2:9.1.083-9.el10_2.7
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(
- affected < 2:8.2.2637-26.el9_8.6fixed 2:8.2.2637-26.el9_8.6
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcar
- affected < 2:9.1.083-9.el10_2.3fixed 2:9.1.083-9.el10_2.3
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in
- affected < 2:8.0.1763-22.el8_10.3fixed 2:8.0.1763-22.el8_10.3
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a
- affected < 2:8.0.1763-22.el8_10.1fixed 2:8.0.1763-22.el8_10.1
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary sh
Page 1 of 3