| Use After Free in GitHub repository vim/vim prior to 9.0.0322. cve CVE-2022-3037 | |
| Use After Free in GitHub repository vim/vim prior to 9.0.0389. cve CVE-2022-3134 | |
| Use After Free in GitHub repository vim/vim prior to 9.0.0530. cve CVE-2022-3256 | |
| Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577. cve CVE-2022-3296 | |
| Use After Free in GitHub repository vim/vim prior to 9.0.0579. cve CVE-2022-3297 | |
| Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598. cve CVE-2022-3324 | |
| Use After Free in GitHub repository vim/vim prior to 9.0.0789. cve CVE-2022-3591 | |
| Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command. cve CVE-2022-4141 | |
| Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. cve CVE-2023-0049 | |
| Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189. cve CVE-2023-0288 | |
| Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. cve CVE-2023-0433 | |
| Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. cve CVE-2023-1170 | |
| Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378. cve CVE-2023-1175 | |
| Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499. cve CVE-2023-2426 | |
| Use After Free in GitHub repository vim/vim prior to 9.0.1840. cve CVE-2023-4733 | |
| Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846. cve CVE-2023-4734 | |
| Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848. cve CVE-2023-4738 | |
| Use After Free in GitHub repository vim/vim prior to 9.0.1857. cve CVE-2023-4750 | |
| Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331. cve CVE-2023-4751 | |
| Use After Free in GitHub repository vim/vim prior to 9.0.1858. cve CVE-2023-4752 | |
| Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873. cve CVE-2023-4781 | |
| Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed by the initial `:s` command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue. cve CVE-2023-48706 | |
| Use After Free in GitHub repository vim/vim prior to v9.0.2010. cve CVE-2023-5535 | |
| Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However, when setting the buffer name to Unnamed, Vim will falsely free a pointer twice, leading to a double-free and possibly later to a heap-use-after-free, which can lead to a crash. The issue has been fixed as of Vim patch v9.1.0648. cve CVE-2024-41965 | |
| vim: arbitrary command execution via modeline sandbox bypass cve CVE-2026-34982 | |
| vim: Vim: Arbitrary Code Execution via crafted directory names cve CVE-2026-47162 | cvss |
| vim: Vim: Arbitrary code execution through Python omni-completion. cve CVE-2026-52860 | cvss |
| vim: Vim: Stack Buffer Overflow via unbounded socket connections cve CVE-2026-73070 | |