Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-35177

Опубликовано: 06 апр. 2026
Источник: debian
EPSS Низкий

Описание

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
vimfixed2:9.2.0315-1package

Примечания

  • https://github.com/vim/vim/security/advisories/GHSA-jc86-w7vm-8p24

  • Fixed by: https://github.com/vim/vim/commit/7088926316d8d4a7572a242d0765e99adfc8b083 (v9.2.0280)

EPSS

Процентиль: 3%
0.00126
Низкий

Связанные уязвимости

CVSS3: 4.1
ubuntu
4 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.

CVSS3: 4.1
redhat
4 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.

CVSS3: 4.1
nvd
4 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.

CVSS3: 4.1
msrc
4 месяца назад

Path traversal issue with zip.vim in Vim

rocky
около 2 месяцев назад

Moderate: vim security update

EPSS

Процентиль: 3%
0.00126
Низкий