Skip to main content

Vendor archive

vim CVEs

Beta · best-effort

251 CVEs tagged to vendor vim14 Critical, 146 High, 75 Medium, 16 Low, 0 Unrated.

CVE-2024-45306

Published Sep 2, 2024

Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that the cursor position always…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41965

Published Aug 1, 2024

Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buf…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-41957

Published Aug 1, 2024

Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and free…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22667

Published Feb 5, 2024

Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-48706

Published Nov 22, 2023

Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-specia…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48237

Published Nov 16, 2023

Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and using a very large value, it may be possible to overflow the…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48236

Published Nov 16, 2023

Vim is an open source command line text editor. When using the z= command, the user may overflow the count with values larger than MAX_INT. Impact is low, user interaction is requ…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48235

Published Nov 16, 2023

Vim is an open source command line text editor. When parsing relative ex addresses one may unintentionally cause an overflow. Ironically this happens in the existing overflow chec…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48234

Published Nov 16, 2023

Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for large counts given. Impact is low, user interaction is requ…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48233

Published Nov 16, 2023

Vim is an open source command line text editor. If the count after the :s command is larger than what fits into a (signed) long variable, abort with e_value_too_large. Impact is l…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48232

Published Nov 16, 2023

Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset for overlong lines and smooth scrolling is enabled and the cp…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-48231

Published Nov 16, 2023

Vim is an open source command line text editor. When closing a window, vim may try to access already freed window structure. Exploitation beyond crashing the application has not b…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-46246

Published Oct 27, 2023

Vim is an improved version of the good old UNIX editor Vi. Heap-use-after-free in memory allocated in the function `ga_grow_inner` in in the file `src/alloc.c` at line 748, which…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 251 CVEsPage 3 of 11