Vendor CVEs
Vim
All CVEs
272 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-55158 | Hig | 0.00 | 8.8 | 0.00 | Aug 11, 2025 | Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operations, an error during evaluation can trigger a double-free in Vim’s internal typed value (typval_T) management.… | ||
| CVE-2025-55157 | Hig | 0.00 | 8.8 | 0.00 | Aug 11, 2025 | Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tuples in Vim script, an error during evaluation can trigger a use-after-free in Vim’s internal tuple reference management. Specifically, the tuple_unref()… | ||
| CVE-2025-53905 | Med | 0.00 | 4.1 | 0.00 | Jul 15, 2025 | Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives. Impact is low because this exploit requires direct user interaction.… | ||
| CVE-2025-29768 | Med | 0.00 | 4.4 | 0.00 | Mar 13, 2025 | Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been… | ||
| CVE-2025-26603 | Med | 0.00 | 4.2 | 0.00 | Feb 18, 2025 | Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:display` ex command. When… | ||
| CVE-2025-1215 | Low | 0.00 | 2.8 | 0.01 | Feb 12, 2025 | A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to… | ||
| CVE-2025-24014 | Med | 0.00 | 4.2 | 0.00 | Jan 20, 2025 | Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the… | ||
| CVE-2024-47814 | Low | 0.00 | 3.9 | 0.00 | Oct 7, 2024 | Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact… | ||
| CVE-2024-45306 | Med | 0.00 | 4.5 | 0.00 | Sep 2, 2024 | Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that the cursor position always points inside a line and does not become invalid by pointing beyond the end of a line. Back then we… | ||
| CVE-2024-43790 | Med | 0.00 | 4.5 | 0.00 | Aug 22, 2024 | Vim is an open source command line text editor. When performing a search and displaying the search-count message is disabled (:set shm+=S), the search pattern is displayed at the bottom of the screen in a buffer (msgbuf). When right-left mode (:set rl) is enabled, the search… | ||
| CVE-2024-41957 | Med | 0.00 | 4.5 | 0.00 | Aug 1, 2024 | Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that… | ||
| CVE-2024-22667 | Hig | 0.00 | 7.8 | 0.01 | Feb 5, 2024 | Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions. | ||
| CVE-2023-5441 | Med | 0.00 | 5.5 | 0.00 | Oct 5, 2023 | NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960. | ||
| CVE-2023-5344 | Hig | 0.00 | 7.5 | 0.01 | Oct 2, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969. | ||
| CVE-2023-3896 | Hig | 0.00 | 7.8 | 0.00 | Aug 7, 2023 | Divide By Zero in vim/vim from 9.0.1367-1 to 9.0.1367-3 | ||
| CVE-2023-2426 | Med | 0.00 | 5.5 | 0.00 | Apr 29, 2023 | Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499. | ||
| CVE-2023-1355 | Med | 0.00 | 5.5 | 0.00 | Mar 11, 2023 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1402. | ||
| CVE-2023-1264 | Med | 0.00 | 5.5 | 0.00 | Mar 7, 2023 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392. | ||
| CVE-2023-1127 | Hig | 0.00 | 7.8 | 0.00 | Mar 1, 2023 | Divide By Zero in GitHub repository vim/vim prior to 9.0.1367. | ||
| CVE-2023-0512 | Hig | 0.00 | 7.8 | 0.00 | Jan 30, 2023 | Divide By Zero in GitHub repository vim/vim prior to 9.0.1247. | ||
| CVE-2023-0433 | Hig | 0.00 | 7.8 | 0.01 | Jan 21, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. | ||
| CVE-2022-47024 | Hig | 0.00 | 7.8 | 0.00 | Jan 20, 2023 | A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts. | ||
| CVE-2023-0288 | Hig | 0.00 | 7.8 | 0.00 | Jan 13, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189. | ||
| CVE-2023-0054 | Hig | 0.00 | 7.8 | 0.00 | Jan 4, 2023 | Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145. | ||
| CVE-2023-0051 | Hig | 0.00 | 7.8 | 0.01 | Jan 4, 2023 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144. | ||
| CVE-2023-0049 | Hig | 0.00 | 7.8 | 0.00 | Jan 4, 2023 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. | ||
| CVE-2022-4293 | Med | 0.00 | 5.5 | 0.00 | Dec 5, 2022 | Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804. | ||
| CVE-2022-4292 | Hig | 0.00 | 7.8 | 0.01 | Dec 5, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0882. | ||
| CVE-2022-3491 | Hig | 0.00 | 7.8 | 0.01 | Dec 3, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742. | ||
| CVE-2022-3520 | Cri | 0.00 | 9.8 | 0.01 | Dec 2, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765. | ||
| CVE-2022-3591 | Hig | 0.00 | 7.8 | 0.00 | Dec 2, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0789. | ||
| CVE-2022-4141 | Hig | 0.00 | 7.8 | 0.00 | Nov 25, 2022 | Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command. | ||
| CVE-2022-3705 | Med | 0.00 | 5.0 | 0.01 | Oct 26, 2022 | A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version… | ||
| CVE-2022-3352 | Hig | 0.00 | 7.8 | 0.00 | Sep 29, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0614. | ||
| CVE-2022-1725 | Med | 0.00 | 5.5 | 0.01 | Sep 29, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959. | ||
| CVE-2022-3324 | Hig | 0.00 | 7.8 | 0.01 | Sep 27, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598. | ||
| CVE-2022-3297 | Hig | 0.00 | 7.8 | 0.01 | Sep 25, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0579. | ||
| CVE-2022-3296 | Hig | 0.00 | 7.8 | 0.01 | Sep 25, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577. | ||
| CVE-2022-3278 | Med | 0.00 | 5.5 | 0.01 | Sep 23, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552. | ||
| CVE-2022-3256 | Hig | 0.00 | 7.8 | 0.00 | Sep 22, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0530. | ||
| CVE-2022-3235 | Hig | 0.00 | 7.8 | 0.01 | Sep 18, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0490. | ||
| CVE-2022-3234 | Hig | 0.00 | 7.8 | 0.01 | Sep 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483. | ||
| CVE-2022-3153 | Med | 0.00 | 5.5 | 0.00 | Sep 8, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404. | ||
| CVE-2022-3134 | Hig | 0.00 | 7.8 | 0.01 | Sep 6, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0389. | ||
| CVE-2022-3099 | Hig | 0.00 | 7.8 | 0.00 | Sep 3, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0360. | ||
| CVE-2022-3037 | Hig | 0.00 | 7.8 | 0.01 | Aug 30, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0322. | ||
| CVE-2022-3016 | Hig | 0.00 | 7.8 | 0.01 | Aug 28, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0286. | ||
| CVE-2022-2982 | Hig | 0.00 | 7.8 | 0.01 | Aug 25, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0260. | ||
| CVE-2022-2980 | Med | 0.00 | 5.5 | 0.01 | Aug 25, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259. | ||
| CVE-2022-2946 | Hig | 0.00 | 7.8 | 0.01 | Aug 23, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0246. |
- risk 0.00cvss 8.8epss 0.00
Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1406, when processing nested tuples during Vim9 script import operations, an error during evaluation can trigger a double-free in Vim’s internal typed value (typval_T) management.…
- risk 0.00cvss 8.8epss 0.00
Vim is an open source, command line text editor. In versions from 9.1.1231 to before 9.1.1400, When processing nested tuples in Vim script, an error during evaluation can trigger a use-after-free in Vim’s internal tuple reference management. Specifically, the tuple_unref()…
- risk 0.00cvss 4.1epss 0.00
Vim is an open source, command line text editor. Prior to version 9.1.1552, a path traversal issue in Vim’s tar.vim plugin can allow overwriting of arbitrary files when opening specially crafted tar archives. Impact is low because this exploit requires direct user interaction.…
- risk 0.00cvss 4.4epss 0.00
Vim, a text editor, is vulnerable to potential data loss with zip.vim and special crafted zip files in versions prior to 9.1.1198. The impact is medium because a user must be made to view such an archive with Vim and then press 'x' on such a strange filename. The issue has been…
- risk 0.00cvss 4.2epss 0.00
Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or `:display` ex command. When…
- risk 0.00cvss 2.8epss 0.01
A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to…
- risk 0.00cvss 4.2epss 0.00
Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the…
- risk 0.00cvss 3.9epss 0.00
Vim is an open source, command line text editor. A use-after-free was found in Vim < 9.1.0764. When closing a buffer (visible in a window) a BufWinLeave auto command can cause an use-after-free if this auto command happens to re-open the same buffer in a new split window. Impact…
- risk 0.00cvss 4.5epss 0.00
Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that the cursor position always points inside a line and does not become invalid by pointing beyond the end of a line. Back then we…
- risk 0.00cvss 4.5epss 0.00
Vim is an open source command line text editor. When performing a search and displaying the search-count message is disabled (:set shm+=S), the search pattern is displayed at the bottom of the screen in a buffer (msgbuf). When right-left mode (:set rl) is enabled, the search…
- risk 0.00cvss 4.5epss 0.00
Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that…
- risk 0.00cvss 7.8epss 0.01
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
- risk 0.00cvss 5.5epss 0.00
NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960.
- risk 0.00cvss 7.5epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
- risk 0.00cvss 7.8epss 0.00
Divide By Zero in vim/vim from 9.0.1367-1 to 9.0.1367-3
- risk 0.00cvss 5.5epss 0.00
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.
- risk 0.00cvss 5.5epss 0.00
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1402.
- risk 0.00cvss 5.5epss 0.00
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392.
- risk 0.00cvss 7.8epss 0.00
Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.
- risk 0.00cvss 7.8epss 0.00
Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
- risk 0.00cvss 7.8epss 0.00
A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts.
- risk 0.00cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
- risk 0.00cvss 7.8epss 0.00
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144.
- risk 0.00cvss 7.8epss 0.00
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
- risk 0.00cvss 5.5epss 0.00
Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0882.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.
- risk 0.00cvss 9.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
- risk 0.00cvss 7.8epss 0.00
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
- risk 0.00cvss 7.8epss 0.00
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
- risk 0.00cvss 5.0epss 0.01
A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version…
- risk 0.00cvss 7.8epss 0.00
Use After Free in GitHub repository vim/vim prior to 9.0.0614.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959.
- risk 0.00cvss 7.8epss 0.01
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0579.
- risk 0.00cvss 7.8epss 0.01
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.
- risk 0.00cvss 7.8epss 0.00
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0490.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
- risk 0.00cvss 5.5epss 0.00
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0389.
- risk 0.00cvss 7.8epss 0.00
Use After Free in GitHub repository vim/vim prior to 9.0.0360.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0322.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0286.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0260.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0246.
Page 3 of 6