rpm package
suse/vim&distro=SUSE Linux Enterprise Server 12 SP2-BCL
pkg:rpm/suse/vim&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL
Vulnerabilities (125)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-4193 | Med | 5.5 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Dec 31, 2021 | vim is vulnerable to Out-of-bounds Read | |
| CVE-2021-4192 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Dec 31, 2021 | vim is vulnerable to Use After Free | |
| CVE-2021-4166 | Hig | 7.1 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Dec 25, 2021 | vim is vulnerable to Out-of-bounds Read | |
| CVE-2021-4136 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Dec 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | |
| CVE-2021-4069 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Dec 6, 2021 | vim is vulnerable to Use After Free | |
| CVE-2021-3984 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Dec 1, 2021 | vim is vulnerable to Heap-based Buffer Overflow | |
| CVE-2021-4019 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Dec 1, 2021 | vim is vulnerable to Heap-based Buffer Overflow | |
| CVE-2021-3973 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Nov 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | |
| CVE-2021-3968 | Hig | 8.0 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Nov 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | |
| CVE-2021-3974 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Nov 19, 2021 | vim is vulnerable to Use After Free | |
| CVE-2021-3928 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Nov 5, 2021 | vim is vulnerable to Use of Uninitialized Variable | |
| CVE-2021-3927 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Nov 5, 2021 | vim is vulnerable to Heap-based Buffer Overflow | |
| CVE-2021-3903 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Oct 27, 2021 | vim is vulnerable to Heap-based Buffer Overflow | |
| CVE-2021-3872 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Oct 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | |
| CVE-2021-3875 | Med | 5.5 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Oct 15, 2021 | vim is vulnerable to Heap-based Buffer Overflow | |
| CVE-2021-3796 | Hig | 7.3 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Sep 15, 2021 | vim is vulnerable to Use After Free | |
| CVE-2021-3778 | Hig | 7.8 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Sep 15, 2021 | vim is vulnerable to Heap-based Buffer Overflow | |
| CVE-2019-20807 | Med | 5.3 | < 7.4.326-17.6.1 | 7.4.326-17.6.1 | May 28, 2020 | In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua). | |
| CVE-2019-12735 | Hig | 8.6 | < 7.4.326-17.3.1 | 7.4.326-17.3.1 | Jun 5, 2019 | getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim. | |
| CVE-2017-17087 | Med | 5.5 | < 9.0.0814-17.9.1 | 9.0.0814-17.9.1 | Dec 1, 2017 | fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, a |
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Out-of-bounds Read
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Use After Free
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Out-of-bounds Read
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Heap-based Buffer Overflow
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Use After Free
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Heap-based Buffer Overflow
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Heap-based Buffer Overflow
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Heap-based Buffer Overflow
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Heap-based Buffer Overflow
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Use After Free
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Use of Uninitialized Variable
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Heap-based Buffer Overflow
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Heap-based Buffer Overflow
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Heap-based Buffer Overflow
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Heap-based Buffer Overflow
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Use After Free
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
vim is vulnerable to Heap-based Buffer Overflow
- affected < 7.4.326-17.6.1fixed 7.4.326-17.6.1
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
- affected < 7.4.326-17.3.1fixed 7.4.326-17.3.1
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
- affected < 9.0.0814-17.9.1fixed 9.0.0814-17.9.1
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, a
Page 6 of 7