Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35177

Опубликовано: 06 апр. 2026
Источник: nvd
CVSS3: 4.1
CVSS3: 7.1
EPSS Низкий

Описание

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
Версия до 9.2.0280 (исключая)

EPSS

Процентиль: 3%
0.00126
Низкий

4.1 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.1
ubuntu
4 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.

CVSS3: 4.1
redhat
4 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.

CVSS3: 4.1
msrc
4 месяца назад

Path traversal issue with zip.vim in Vim

CVSS3: 4.1
debian
4 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0280, a ...

rocky
около 2 месяцев назад

Moderate: vim security update

EPSS

Процентиль: 3%
0.00126
Низкий

4.1 Medium

CVSS3

7.1 High

CVSS3

Дефекты

CWE-22