Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-73072

Опубликовано: 11 авг. 2026
Источник: nvd
EPSS Низкий

Описание

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.

EPSS

Процентиль: 2%
0.00125
Низкий

Дефекты

CWE-122

Связанные уязвимости

ubuntu
17 дней назад

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.

CVSS3: 7.8
redhat
17 дней назад

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846.

msrc
6 дней назад

Vim: Heap Buffer Overflow when Loading a Spell File

debian
17 дней назад

Vim is an open source, command line text editor. Prior to 9.2.0846, se ...

EPSS

Процентиль: 2%
0.00125
Низкий

Дефекты

CWE-122