VYPR

Vim

by Vim

Source repositories

CVEs (268)

  • CVE-2020-20703CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.

  • CVE-2017-6350CriFeb 27, 2017
    risk 0.64cvss 9.8epss 0.03

    An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.

  • CVE-2017-6349CriFeb 27, 2017
    risk 0.64cvss 9.8epss 0.03

    An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.

  • CVE-2017-5953CriFeb 10, 2017
    risk 0.64cvss 9.8epss 0.03

    vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.

  • CVE-2026-34714CriMar 30, 2026
    risk 0.53cvss 9.2epss 0.01

    Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

  • CVE-2023-4781HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

  • CVE-2023-4750HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.1857.

  • CVE-2023-4733HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.1840.

  • CVE-2023-4736HigSep 2, 2023
    risk 0.51cvss 7.8epss 0.00

    Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

  • CVE-2023-4735HigSep 2, 2023
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

  • CVE-2023-4734HigSep 2, 2023
    risk 0.51cvss 7.8epss 0.01

    Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

  • CVE-2023-2610HigMay 9, 2023
    risk 0.51cvss 7.8epss 0.00

    Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.

  • CVE-2021-4019HigDec 1, 2021
    risk 0.51cvss 7.8epss 0.02

    vim is vulnerable to Heap-based Buffer Overflow

  • CVE-2017-11109HigJul 8, 2017
    risk 0.51cvss 7.8epss 0.01

    Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NOTE: there might be a limited number of scenarios in which this has security relevance.

  • CVE-2026-51401HigAug 4, 2026
    risk 0.50cvss 7.7epss 0.00

    An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

  • CVE-2026-47162HigJun 11, 2026
    risk 0.50cvss 8.8epss 0.00

    Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file…

  • CVE-2026-73078HigAug 11, 2026
    risk 0.49cvss epss 0.00

    Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into…

  • CVE-2026-73077HigAug 11, 2026
    risk 0.48cvss epss 0.00

    Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating…

  • CVE-2026-73076HigAug 11, 2026
    risk 0.48cvss epss 0.00

    Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record…

  • CVE-2026-73072HigAug 11, 2026
    risk 0.48cvss epss 0.00

    Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping…

Page 1 of 14