Vendor CVEs
Vim
All CVEs
272 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-20703 | Cri | 0.64 | 9.8 | 0.02 | Jun 20, 2023 | Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter. | ||
| CVE-2017-6350 | Cri | 0.64 | 9.8 | 0.03 | Feb 27, 2017 | An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows. | ||
| CVE-2017-6349 | Cri | 0.64 | 9.8 | 0.03 | Feb 27, 2017 | An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows. | ||
| CVE-2017-5953 | Cri | 0.64 | 9.8 | 0.03 | Feb 10, 2017 | vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow. | ||
| CVE-2019-12735 | Hig | 0.60 | 8.6 | 0.19 | Jun 5, 2019 | getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim. | ||
| CVE-2026-34714 | Cri | 0.53 | 9.2 | 0.00 | Mar 30, 2026 | Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE. | ||
| CVE-2021-3968 | Hig | 0.52 | 8.0 | 0.02 | Nov 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2023-5535 | Hig | 0.51 | 7.8 | 0.01 | Oct 11, 2023 | Use After Free in GitHub repository vim/vim prior to v9.0.2010. | ||
| CVE-2023-4781 | Hig | 0.51 | 7.8 | 0.01 | Sep 5, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873. | ||
| CVE-2023-4752 | Hig | 0.51 | 7.8 | 0.01 | Sep 4, 2023 | Use After Free in GitHub repository vim/vim prior to 9.0.1858. | ||
| CVE-2023-4750 | Hig | 0.51 | 7.8 | 0.01 | Sep 4, 2023 | Use After Free in GitHub repository vim/vim prior to 9.0.1857. | ||
| CVE-2023-4733 | Hig | 0.51 | 7.8 | 0.01 | Sep 4, 2023 | Use After Free in GitHub repository vim/vim prior to 9.0.1840. | ||
| CVE-2023-4751 | Hig | 0.51 | 7.8 | 0.01 | Sep 3, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331. | ||
| CVE-2023-4738 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848. | ||
| CVE-2023-4736 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833. | ||
| CVE-2023-4735 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847. | ||
| CVE-2023-4734 | Hig | 0.51 | 7.8 | 0.01 | Sep 2, 2023 | Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846. | ||
| CVE-2023-2610 | Hig | 0.51 | 7.8 | 0.00 | May 9, 2023 | Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532. | ||
| CVE-2023-0433 | Hig | 0.51 | 7.8 | 0.01 | Jan 21, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. | ||
| CVE-2023-0288 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189. | ||
| CVE-2023-0049 | Hig | 0.51 | 7.8 | 0.01 | Jan 4, 2023 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. | ||
| CVE-2022-3591 | Hig | 0.51 | 7.8 | 0.00 | Dec 2, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0789. | ||
| CVE-2022-4141 | Hig | 0.51 | 7.8 | 0.00 | Nov 25, 2022 | Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command. | ||
| CVE-2022-3324 | Hig | 0.51 | 7.8 | 0.01 | Sep 27, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598. | ||
| CVE-2022-3297 | Hig | 0.51 | 7.8 | 0.01 | Sep 25, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0579. | ||
| CVE-2022-3296 | Hig | 0.51 | 7.8 | 0.01 | Sep 25, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577. | ||
| CVE-2022-3256 | Hig | 0.51 | 7.8 | 0.00 | Sep 22, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0530. | ||
| CVE-2022-3134 | Hig | 0.51 | 7.8 | 0.01 | Sep 6, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0389. | ||
| CVE-2022-3037 | Hig | 0.51 | 7.8 | 0.01 | Aug 30, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0322. | ||
| CVE-2022-37173 | Hig | 0.51 | 7.8 | 0.00 | Aug 30, 2022 | An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe. | ||
| CVE-2021-4192 | Hig | 0.51 | 7.8 | 0.02 | Dec 31, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4187 | Hig | 0.51 | 7.8 | 0.02 | Dec 29, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4173 | Hig | 0.51 | 7.8 | 0.02 | Dec 27, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4136 | Hig | 0.51 | 7.8 | 0.02 | Dec 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-4069 | Hig | 0.51 | 7.8 | 0.01 | Dec 6, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-3984 | Hig | 0.51 | 7.8 | 0.02 | Dec 1, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-4019 | Hig | 0.51 | 7.8 | 0.02 | Dec 1, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-3973 | Hig | 0.51 | 7.8 | 0.02 | Nov 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-3974 | Hig | 0.51 | 7.8 | 0.01 | Nov 19, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-3928 | Hig | 0.51 | 7.8 | 0.01 | Nov 5, 2021 | vim is vulnerable to Use of Uninitialized Variable | ||
| CVE-2021-3927 | Hig | 0.51 | 7.8 | 0.02 | Nov 5, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-3903 | Hig | 0.51 | 7.8 | 0.01 | Oct 27, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-3872 | Hig | 0.51 | 7.8 | 0.01 | Oct 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-3778 | Hig | 0.51 | 7.8 | 0.02 | Sep 15, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-3770 | Hig | 0.51 | 7.8 | 0.01 | Sep 6, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2019-20079 | Hig | 0.51 | 7.8 | 0.02 | Dec 30, 2019 | The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory. | ||
| CVE-2017-11109 | Hig | 0.51 | 7.8 | 0.01 | Jul 8, 2017 | Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NOTE: there might be a limited number of scenarios in which this has security relevance. | ||
| CVE-2026-51401 | Hig | 0.50 | 7.7 | 0.00 | Aug 4, 2026 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c | ||
| CVE-2026-47162 | Hig | 0.50 | 8.8 | 0.00 | Jun 11, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file… | ||
| CVE-2026-73078 | Hig | 0.49 | — | 0.00 | Aug 11, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into… |
- risk 0.64cvss 9.8epss 0.02
Buffer Overflow vulnerability in VIM v.8.1.2135 allows a remote attacker to execute arbitrary code via the operand parameter.
- risk 0.64cvss 9.8epss 0.03
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
- risk 0.64cvss 9.8epss 0.03
An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
- risk 0.64cvss 9.8epss 0.03
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
- risk 0.60cvss 8.6epss 0.19
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
- risk 0.53cvss 9.2epss 0.00
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
- risk 0.52cvss 8.0epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.51cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to v9.0.2010.
- risk 0.51cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
- risk 0.51cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.1858.
- risk 0.51cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.1857.
- risk 0.51cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.1840.
- risk 0.51cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
- risk 0.51cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
- risk 0.51cvss 7.8epss 0.01
Untrusted Search Path in GitHub repository vim/vim prior to 9.0.1833.
- risk 0.51cvss 7.8epss 0.01
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.
- risk 0.51cvss 7.8epss 0.01
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
- risk 0.51cvss 7.8epss 0.00
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.
- risk 0.51cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
- risk 0.51cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
- risk 0.51cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
- risk 0.51cvss 7.8epss 0.00
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
- risk 0.51cvss 7.8epss 0.00
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
- risk 0.51cvss 7.8epss 0.01
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
- risk 0.51cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0579.
- risk 0.51cvss 7.8epss 0.01
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
- risk 0.51cvss 7.8epss 0.00
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
- risk 0.51cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0389.
- risk 0.51cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0322.
- risk 0.51cvss 7.8epss 0.00
An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.
- risk 0.51cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.51cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.51cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.51cvss 7.8epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.51cvss 7.8epss 0.01
vim is vulnerable to Use After Free
- risk 0.51cvss 7.8epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.51cvss 7.8epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.51cvss 7.8epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.51cvss 7.8epss 0.01
vim is vulnerable to Use After Free
- risk 0.51cvss 7.8epss 0.01
vim is vulnerable to Use of Uninitialized Variable
- risk 0.51cvss 7.8epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.51cvss 7.8epss 0.01
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.51cvss 7.8epss 0.01
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.51cvss 7.8epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.51cvss 7.8epss 0.01
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.51cvss 7.8epss 0.02
The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
- risk 0.51cvss 7.8epss 0.01
Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NOTE: there might be a limited number of scenarios in which this has security relevance.
- risk 0.50cvss 7.7epss 0.00
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c
- risk 0.50cvss 8.8epss 0.00
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing browsed directory paths to the history file…
- risk 0.49cvss —epss 0.00
Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into…
Page 1 of 6