Vim
by Vim
Source repositories
CVEs (270)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-20703 | Cri | 0.64 | 9.8 | 0.02 | Jun 20, 2023 | Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter. | ||
| CVE-2017-6350 | Cri | 0.64 | 9.8 | 0.03 | Feb 27, 2017 | An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows. | ||
| CVE-2017-6349 | Cri | 0.64 | 9.8 | 0.03 | Feb 27, 2017 | An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows. | ||
| CVE-2017-5953 | Cri | 0.64 | 9.8 | 0.03 | Feb 10, 2017 | vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow. | ||
| CVE-2019-12735 | Hig | 0.60 | 8.6 | 0.19 | Jun 5, 2019 | getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim. | ||
| CVE-2026-34714 | Cri | 0.53 | 9.2 | 0.00 | Mar 30, 2026 | Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE. | ||
| CVE-2021-3968 | Hig | 0.52 | 8.0 | 0.02 | Nov 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2023-5535 | Hig | 0.51 | 7.8 | 0.01 | Oct 11, 2023 | Use After Free in GitHub repository vim/vim prior to v9.0.2010. | ||
| CVE-2023-4781 | Hig | 0.51 | 7.8 | 0.01 | Sep 5, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873. | ||
| CVE-2023-4752 | Hig | 0.51 | 7.8 | 0.01 | Sep 4, 2023 | Use After Free in GitHub repository vim/vim prior to 9.0.1858. | ||
| CVE-2023-4750 | Hig | 0.51 | 7.8 | 0.01 | Sep 4, 2023 | Use After Free in GitHub repository vim/vim prior to 9.0.1857. | ||
| CVE-2023-4733 | Hig | 0.51 | 7.8 | 0.01 | Sep 4, 2023 | Use After Free in GitHub repository vim/vim prior to 9.0.1840. | ||
| CVE-2023-4751 | Hig | 0.51 | 7.8 | 0.01 | Sep 3, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331. | ||
| CVE-2023-4738 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848. | ||
| CVE-2023-4736 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833. | ||
| CVE-2023-4735 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847. | ||
| CVE-2023-4734 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846. | ||
| CVE-2023-2610 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532. | ||
| CVE-2023-0433 | Hig | 0.51 | 7.8 | 0.01 | Jan 21, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. | ||
| CVE-2023-0288 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189. |
- risk 0.64cvss 9.8epss 0.02
Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.
- risk 0.64cvss 9.8epss 0.03
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
- risk 0.64cvss 9.8epss 0.03
An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
- risk 0.64cvss 9.8epss 0.03
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
- risk 0.60cvss 8.6epss 0.19
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
- risk 0.53cvss 9.2epss 0.00
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
- risk 0.52cvss 8.0epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.51cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to v9.0.2010.
- risk 0.51cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
- risk 0.51cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.1858.
- risk 0.51cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.1857.
- risk 0.51cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.1840.
- risk 0.51cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
- risk 0.51cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
- risk 0.51cvss 7.8epss 0.01
Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.
- risk 0.51cvss 7.8epss 0.01
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.
- risk 0.51cvss 7.8epss 0.01
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
- risk 0.51cvss 7.8epss 0.00
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.
- risk 0.51cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
- risk 0.51cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
Page 1 of 14