VYPR
Vendor

Vim

Products
9
CVEs
272
Across products
285
Status
Private

Products

9

Recent CVEs

272
View all 272 CVEs →
  • CVE-2020-20703CriJun 20, 2023
    risk 0.64cvss 9.8epss 0.02

    Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.

  • CVE-2017-6350CriFeb 27, 2017
    risk 0.64cvss 9.8epss 0.03

    An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.

  • CVE-2017-6349CriFeb 27, 2017
    risk 0.64cvss 9.8epss 0.03

    An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.

  • CVE-2017-5953CriFeb 10, 2017
    risk 0.64cvss 9.8epss 0.03

    vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.

  • CVE-2019-12735HigJun 5, 2019
    risk 0.60cvss 8.6epss 0.19

    getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.

  • CVE-2026-34714CriMar 30, 2026
    risk 0.53cvss 9.2epss 0.00

    Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

  • CVE-2021-3968HigNov 19, 2021
    risk 0.52cvss 8.0epss 0.02

    vim is vulnerable to Heap-based Buffer Overflow

  • CVE-2023-5535HigOct 11, 2023
    risk 0.51cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to v9.0.2010.

  • CVE-2023-4781HigSep 5, 2023
    risk 0.51cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.

  • CVE-2023-4752HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.1858.

  • CVE-2023-4750HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.1857.

  • CVE-2023-4733HigSep 4, 2023
    risk 0.51cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 9.0.1840.

  • CVE-2023-4751HigSep 3, 2023
    risk 0.51cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.

  • CVE-2023-4738HigSep 2, 2023
    risk 0.51cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.

  • CVE-2023-4736HigSep 2, 2023
    risk 0.51cvss 7.8epss 0.01

    Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.

  • CVE-2023-4735HigSep 2, 2023
    risk 0.51cvss 7.8epss 0.01

    Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.

  • CVE-2023-4734HigSep 2, 2023
    risk 0.51cvss 7.8epss 0.01

    Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.

  • CVE-2023-2610HigMay 9, 2023
    risk 0.51cvss 7.8epss 0.00

    Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.

  • CVE-2023-0433HigJan 21, 2023
    risk 0.51cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.

  • CVE-2023-0288HigJan 13, 2023
    risk 0.51cvss 7.8epss 0.00

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.