Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2023-0054
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145.
Vim
9.0.1145+
HIGH 7.8
CVE-2023-0051
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144.
Vim
9.0.1144+
HIGH 7.8
CVE-2022-4292
Use After Free in GitHub repository vim/vim prior to 9.0.0882.
Vim
9.0.0882+
MEDIUM 5.5
CVE-2022-4293
Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804.
Vim
9.0.0804+
HIGH 7.8
CVE-2022-3491
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742.
Vim
9.0.0742+
CRITICAL 9.8
CVE-2022-3520
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
Vim
9.0.0765+
HIGH 7.8
CVE-2022-3591
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
Vim
9.0.0789+
MEDIUM 5.5
CVE-2022-1725
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4959.
Vim
8.2.4959 / 13.0+
MEDIUM 5.5
CVE-2022-3153
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404.
Vim
9.0.0404+
HIGH 7.8
CVE-2022-37173
An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe.
Gvim
Mitigation only
MEDIUM 5.5
CVE-2022-2874
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0224.
Vim
9.0.0224+
HIGH 7.8
CVE-2022-2580
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102.
Vim
9.0.0102+
HIGH 7.8
CVE-2022-2581
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104.
Vim
9.0.0104+
HIGH 7.8
CVE-2022-2571
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101.
Vim
9.0.0101+
HIGH 7.8
CVE-2022-2522
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.
Vim
9.0.0061+
HIGH 7.8
CVE-2022-2042
Use After Free in GitHub repository vim/vim prior to 8.2.
Vim
8.2.5072 / 11.7+
HIGH 7.8
CVE-2022-1796
Use After Free in GitHub repository vim/vim prior to 8.2.4979.
Vim
8.2.4979+
MEDIUM 5.5
CVE-2022-1771
Uncontrolled Recursion in GitHub repository vim/vim prior to 8.2.4975.
Vim
8.2.4975+
HIGH 7.8
CVE-2022-1735
Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2.4969.
Vim
8.2.4969 / 13.0+
HIGH 7.8
CVE-2022-0407
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Vim
8.2.4219+
HIGH 7.8
CVE-2022-0128
vim is vulnerable to Out-of-bounds Read
Vim
8.2.4009 / 10.15.7+
HIGH 8.6
CVE-2019-12735EPSS 19%
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a model…
Vim
0.3.6 / 8.1.1365+
MEDIUM 5.5
CVE-2017-1000382
VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may…
Vim
after 8.0.1187
HIGH 7.8
CVE-2017-11109
Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NO…
Vim
Mitigation only
CRITICAL 9.8
CVE-2017-6349
An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tr…
Vim
after 8.0.0376
CRITICAL 9.8
CVE-2017-6350
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values f…
Vim
after 8.0.0377
CRITICAL 9.8
CVE-2017-5953
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a …
Vim
after 8.0.0055
HIGH 9.3
CVE-2010-3914EPSS 9%
Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and …
Gvim
after 7.3.033
HIGH 9.3
CVE-2008-6235
The Netrw plugin (netrw.vim) in Vim 7.0 and 7.1 allows user-assisted attackers to execute arbitrary commands via shell metacharacters in a filename u…
Vim
Patch available
HIGH 9.3
CVE-2008-3074
The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation…
Tar.vim
Patch available