Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-34714

Опубликовано: 30 мар. 2026
Источник: nvd
CVSS3: 9.2
CVSS3: 8.6
EPSS Низкий

Описание

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
Версия от 9.1.1390 (включая) до 9.2.0272 (исключая)

EPSS

Процентиль: 44%
0.00588
Низкий

9.2 Critical

CVSS3

8.6 High

CVSS3

Дефекты

CWE-78
CWE-917

Связанные уязвимости

CVSS3: 9.2
ubuntu
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 8.6
redhat
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 8.5
msrc
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 9.2
debian
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upo ...

CVSS3: 9.2
github
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

EPSS

Процентиль: 44%
0.00588
Низкий

9.2 Critical

CVSS3

8.6 High

CVSS3

Дефекты

CWE-78
CWE-917