Vulnerability index

Browse CVEs

95 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vim HIGH 7.8
CVE-2023-0054

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.

Fix: 9.0.1145+
Fix from $1,950 2023-01-04
Vim HIGH 7.8
CVE-2023-0051

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144.

Fix: 9.0.1144+
Fix from $1,950 2023-01-04
Vim HIGH 7.8
CVE-2022-4292

Use After Free in GitHub repository vim/vim prior to 9.0.0882.

Fix: 9.0.0882+
Fix from $1,950 2022-12-05
Vim MEDIUM 5.5
CVE-2022-4293

Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.

Fix: 9.0.0804+
Fix from $1,600 2022-12-05
Vim HIGH 7.8
CVE-2022-3491

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.

Fix: 9.0.0742+
Fix from $1,950 2022-12-03
Vim CRITICAL 9.8
CVE-2022-3520

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.

Fix: 9.0.0765+
Fix from $2,300 2022-12-02
Vim HIGH 7.8
CVE-2022-3591

Use After Free in GitHub repository vim/vim prior to 9.0.0789.

Fix: 9.0.0789+
Fix from $1,950 2022-12-02
Vim MEDIUM 5.5
CVE-2022-1725

NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959.

Fix: 8.2.4959 / 13.0+
Fix from $1,600 2022-09-29
Vim MEDIUM 5.5
CVE-2022-3153

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404.

Fix: 9.0.0404+
Fix from $1,600 2022-09-08
Gvim HIGH 7.8
CVE-2022-37173

An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.

Mitigation only
Fix from $1,950 2022-08-30
Vim MEDIUM 5.5
CVE-2022-2874

NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0224.

Fix: 9.0.0224+
Fix from $1,600 2022-08-18
Vim HIGH 7.8
CVE-2022-2580

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102.

Fix: 9.0.0102+
Fix from $1,950 2022-08-01
Vim HIGH 7.8
CVE-2022-2581

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104.

Fix: 9.0.0104+
Fix from $1,950 2022-08-01
Vim HIGH 7.8
CVE-2022-2571

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101.

Fix: 9.0.0101+
Fix from $1,950 2022-08-01
Vim HIGH 7.8
CVE-2022-2522

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.

Fix: 9.0.0061+
Fix from $1,950 2022-07-25
Vim HIGH 7.8
CVE-2022-2042

Use After Free in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.5072 / 11.7+
Fix from $1,950 2022-06-10
Vim HIGH 7.8
CVE-2022-1796

Use After Free in GitHub repository vim/vim prior to 8.2.4979.

Fix: 8.2.4979+
Fix from $1,950 2022-05-19
Vim MEDIUM 5.5
CVE-2022-1771

Uncontrolled Recursion in GitHub repository vim/vim prior to 8.2.4975.

Fix: 8.2.4975+
Fix from $1,600 2022-05-18
Vim HIGH 7.8
CVE-2022-1735

Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2.4969.

Fix: 8.2.4969 / 13.0+
Fix from $1,950 2022-05-17
Vim HIGH 7.8
CVE-2022-0407

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

Fix: 8.2.4219+
Fix from $1,950 2022-01-30
Vim HIGH 7.8
CVE-2022-0128

vim is vulnerable to Out-of-bounds Read

Fix: 8.2.4009 / 10.15.7+
Fix from $1,950 2022-01-06
Vim HIGH 8.6
CVE-2019-12735EPSS 19%

getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a model…

Fix: 0.3.6 / 8.1.1365+
Fix from $1,950 2019-06-05
Vim MEDIUM 5.5
CVE-2017-1000382

VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may…

Fix: after 8.0.1187
Fix from $1,600 2017-10-31
Vim HIGH 7.8
CVE-2017-11109

Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NO…

Mitigation only
Fix from $1,950 2017-07-08
Vim CRITICAL 9.8
CVE-2017-6349

An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tr…

Fix: after 8.0.0376
Fix from $2,300 2017-02-27
Vim CRITICAL 9.8
CVE-2017-6350

An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values f…

Fix: after 8.0.0377
Fix from $2,300 2017-02-27
Vim CRITICAL 9.8
CVE-2017-5953

vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a …

Fix: after 8.0.0055
Fix from $2,300 2017-02-10
Gvim HIGH 9.3
CVE-2010-3914EPSS 9%

Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and …

Fix: after 7.3.033
Fix from $1,950 2010-11-03
Vim HIGH 9.3
CVE-2008-6235

The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename u…

Patch available
Fix from $1,950 2009-02-21
Tar.vim HIGH 9.3
CVE-2008-3074

The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation…

Patch available
Fix from $1,950 2009-02-21