rpm package
opensuse/vim&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/vim&distro=openSUSE%20Tumbleweed
Vulnerabilities (125)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2022-0554 | Hig | 7.8 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Feb 10, 2022 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0443 | Hig | 7.8 | < 8.2.4286-1.1 | 8.2.4286-1.1 | Feb 2, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0417 | Hig | 7.8 | < 8.2.4286-1.1 | 8.2.4286-1.1 | Feb 1, 2022 | Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0413 | Hig | 7.8 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 30, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0408 | Hig | 7.8 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 30, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0407 | Hig | 7.8 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 30, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0393 | Hig | 7.1 | < 8.2.4286-1.1 | 8.2.4286-1.1 | Jan 28, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0392 | Hig | 7.8 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 28, 2022 | Heap-based Buffer Overflow in GitHub repository vim prior to 8.2. | |
| CVE-2022-0368 | Hig | 7.8 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 26, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0361 | Hig | 7.8 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 26, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0359 | Hig | 7.8 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 26, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0351 | Hig | 7.8 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 25, 2022 | Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0319 | Med | 5.5 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 21, 2022 | Out-of-bounds Read in vim/vim prior to 8.2. | |
| CVE-2022-0318 | Cri | 9.8 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 21, 2022 | Heap-based Buffer Overflow in vim/vim prior to 8.2. | |
| CVE-2022-0261 | Hig | 7.8 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 18, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | |
| CVE-2022-0213 | Med | 6.6 | < 9.0.0453-2.1 | 9.0.0453-2.1 | Jan 14, 2022 | vim is vulnerable to Heap-based Buffer Overflow | |
| CVE-2022-0156 | Med | 5.5 | < 8.2.4063-1.1 | 8.2.4063-1.1 | Jan 10, 2022 | vim is vulnerable to Use After Free | |
| CVE-2019-12735 | Hig | 8.6 | < 8.2.3408-1.2 | 8.2.3408-1.2 | Jun 5, 2019 | getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim. | |
| CVE-2017-1000382 | Med | 5.5 | < 8.2.3408-1.2 | 8.2.3408-1.2 | Oct 31, 2017 | VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary. | |
| CVE-2017-6350 | Cri | 9.8 | < 8.2.3408-1.2 | 8.2.3408-1.2 | Feb 27, 2017 | An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows. |
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
- affected < 8.2.4286-1.1fixed 8.2.4286-1.1
Use After Free in GitHub repository vim/vim prior to 8.2.
- affected < 8.2.4286-1.1fixed 8.2.4286-1.1
Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Use After Free in GitHub repository vim/vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- affected < 8.2.4286-1.1fixed 8.2.4286-1.1
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Out-of-bounds Read in vim/vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Heap-based Buffer Overflow in vim/vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- affected < 9.0.0453-2.1fixed 9.0.0453-2.1
vim is vulnerable to Heap-based Buffer Overflow
- affected < 8.2.4063-1.1fixed 8.2.4063-1.1
vim is vulnerable to Use After Free
- affected < 8.2.3408-1.2fixed 8.2.3408-1.2
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
- affected < 8.2.3408-1.2fixed 8.2.3408-1.2
VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the vi binary.
- affected < 8.2.3408-1.2fixed 8.2.3408-1.2
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
Page 6 of 7