Things

28 things. Its feed

Use After Free in GitHub repository vim/vim prior to 9.0.0322.
cve CVE-2022-3037
Use After Free in GitHub repository vim/vim prior to 9.0.0389.
cve CVE-2022-3134
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
cve CVE-2022-3256
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
cve CVE-2022-3296
Use After Free in GitHub repository vim/vim prior to 9.0.0579.
cve CVE-2022-3297
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
cve CVE-2022-3324
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
cve CVE-2022-3591
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
cve CVE-2022-4141
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
cve CVE-2023-0049
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
cve CVE-2023-0288
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225.
cve CVE-2023-0433
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376.
cve CVE-2023-1170
Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378.
cve CVE-2023-1175
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 9.0.1499.
cve CVE-2023-2426
Use After Free in GitHub repository vim/vim prior to 9.0.1840.
cve CVE-2023-4733
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1846.
cve CVE-2023-4734
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1848.
cve CVE-2023-4738
Use After Free in GitHub repository vim/vim prior to 9.0.1857.
cve CVE-2023-4750
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1331.
cve CVE-2023-4751
Use After Free in GitHub repository vim/vim prior to 9.0.1858.
cve CVE-2023-4752
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1873.
cve CVE-2023-4781
Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive `:s` call causes free-ing of memory which may later then be accessed by the initial `:s` command. The user must intentionally execute the payload and the whole process is a bit tricky to do since it seems to work only reliably for the very first :s command. It may also cause a crash of Vim. Version 9.0.2121 contains a fix for this issue.
cve CVE-2023-48706
Use After Free in GitHub repository vim/vim prior to v9.0.2010.
cve CVE-2023-5535
Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However, when setting the buffer name to Unnamed, Vim will falsely free a pointer twice, leading to a double-free and possibly later to a heap-use-after-free, which can lead to a crash. The issue has been fixed as of Vim patch v9.1.0648.
cve CVE-2024-41965
vim: arbitrary command execution via modeline sandbox bypass
cve CVE-2026-34982
vim: Vim: Arbitrary Code Execution via crafted directory names
cve CVE-2026-47162
cvss
vim: Vim: Arbitrary code execution through Python omni-completion.
cve CVE-2026-52860
cvss
vim: Vim: Stack Buffer Overflow via unbounded socket connections
cve CVE-2026-73070