VYPR

rpm package

opensuse/vim&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/vim&distro=openSUSE%20Tumbleweed

Vulnerabilities (125)

  • CVE-2026-46483LowMay 15, 2026
    affected < 9.2.0530-1.1fixed 9.2.0530-1.1

    Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-like systems. The function builds :!gunzip and :!gzip -d commands using shellescape(

  • CVE-2026-45130MedMay 8, 2026
    affected < 9.2.0530-1.1fixed 9.2.0530-1.1

    Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 encoding active. An attacker-controlled length field in the spell file's compound se

  • CVE-2026-44656MedMay 8, 2026
    affected < 9.2.0530-1.1fixed 9.2.0530-1.1

    Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion

  • CVE-2026-42307MedMay 8, 2026
    affected < 9.2.0530-1.1fixed 9.2.0530-1.1

    Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can

  • CVE-2026-39881MedApr 8, 2026
    affected < 9.2.0398-1.1fixed 9.2.0398-1.1

    Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands when Vim connects to it, via unsanitized strings in the defineAnnoType and special

  • CVE-2026-34982HigApr 6, 2026
    affected < 9.2.0398-1.1fixed 9.2.0398-1.1

    Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a

  • CVE-2026-34714CriMar 30, 2026
    affected < 9.2.0398-1.1fixed 9.2.0398-1.1

    Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

  • CVE-2026-33412Mar 24, 2026
    affected < 9.2.0398-1.1fixed 9.2.0398-1.1

    Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary sh

  • CVE-2023-4751HigSep 3, 2023
    affected < 9.0.1894-1.1fixed 9.0.1894-1.1

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

  • CVE-2023-4738HigSep 2, 2023
    affected < 9.0.1894-1.1fixed 9.0.1894-1.1

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

  • CVE-2023-4735HigSep 2, 2023
    affected < 9.0.1894-1.1fixed 9.0.1894-1.1

    Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

  • CVE-2023-4734HigSep 2, 2023
    affected < 9.0.1894-1.1fixed 9.0.1894-1.1

    Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

  • CVE-2023-2609MedMay 9, 2023
    affected < 9.0.1538-1.1fixed 9.0.1538-1.1

    NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.

  • CVE-2023-2426MedApr 29, 2023
    affected < 9.0.1504-1.1fixed 9.0.1504-1.1

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.

  • CVE-2023-1355MedMar 11, 2023
    affected < 9.0.1430-1.1fixed 9.0.1430-1.1

    NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1402.

  • CVE-2023-1264MedMar 7, 2023
    affected < 9.0.1392-1.1fixed 9.0.1392-1.1

    NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392.

  • CVE-2023-1175MedMar 4, 2023
    affected < 9.0.1392-1.1fixed 9.0.1392-1.1

    Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.

  • CVE-2023-1127HigMar 1, 2023
    affected < 9.0.1367-1.1fixed 9.0.1367-1.1

    Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.

  • CVE-2022-3352HigSep 29, 2022
    affected < 9.0.0626-1.1fixed 9.0.0626-1.1

    Use After Free in GitHub repository vim/vim prior to 9.0.0614.

  • CVE-2022-3235HigSep 18, 2022
    affected < 9.0.0500-1.1fixed 9.0.0500-1.1

    Use After Free in GitHub repository vim/vim prior to 9.0.0490.

Page 1 of 7

VYPR — Vulnerability Intelligence