Описание
Security update for vim
This update for vim fixes the following issues:
Updated to version 9.0.0814:
- Fixing bsc#1192478 VUL-1: CVE-2021-3928: vim: vim is vulnerable to Stack-based Buffer Overflow
- Fixing bsc#1203508 VUL-0: CVE-2022-3234: vim: Heap-based Buffer Overflow prior to 9.0.0483.
- Fixing bsc#1203509 VUL-1: CVE-2022-3235: vim: Use After Free in GitHub prior to 9.0.0490.
- Fixing bsc#1203820 VUL-0: CVE-2022-3324: vim: Stack-based Buffer Overflow in prior to 9.0.0598.
- Fixing bsc#1204779 VUL-0: CVE-2022-3705: vim: use after free in function qf_update_buffer of the file quickfix.c
- Fixing bsc#1203152 VUL-1: CVE-2022-2982: vim: use after free in qf_fill_buffer()
- Fixing bsc#1203796 VUL-1: CVE-2022-3296: vim: stack out of bounds read in ex_finally() in ex_eval.c
- Fixing bsc#1203797 VUL-1: CVE-2022-3297: vim: use-after-free in process_next_cpt_value() at insexpand.c
- Fixing bsc#1203110 VUL-1: CVE-2022-3099: vim: Use After Free in ex_docmd.c
- Fixing bsc#1203194 VUL-1: CVE-2022-3134: vim: use after free in do_tag()
- Fixing bsc#1203272 VUL-1: CVE-2022-3153: vim: NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404.
- Fixing bsc#1203799 VUL-1: CVE-2022-3278: vim: NULL pointer dereference in eval_next_non_blank() in eval.c
- Fixing bsc#1203924 VUL-1: CVE-2022-3352: vim: vim: use after free
- Fixing bsc#1203155 VUL-1: CVE-2022-2980: vim: null pointer dereference in do_mouse()
- Fixing bsc#1202962 VUL-1: CVE-2022-3037: vim: Use After Free in vim prior to 9.0.0321
- Fixing bsc#1200884 Vim: Error on startup
- Fixing bsc#1200902 VUL-0: CVE-2022-2183: vim: Out-of-bounds Read through get_lisp_indent() Mon 13:32
- Fixing bsc#1200903 VUL-0: CVE-2022-2182: vim: Heap-based Buffer Overflow through parse_cmd_address() Tue 08:37
- Fixing bsc#1200904 VUL-0: CVE-2022-2175: vim: Buffer Over-read through cmdline_insert_reg() Tue 08:37
- Fixing bsc#1201249 VUL-0: CVE-2022-2304: vim: stack buffer overflow in spell_dump_compl()
- Fixing bsc#1201356 VUL-1: CVE-2022-2343: vim: Heap-based Buffer Overflow in GitHub repository vim prior to 9.0.0044
- Fixing bsc#1201359 VUL-1: CVE-2022-2344: vim: Another Heap-based Buffer Overflow vim prior to 9.0.0045
- Fixing bsc#1201363 VUL-1: CVE-2022-2345: vim: Use After Free in GitHub repository vim prior to 9.0.0046.
- Fixing bsc#1201620 vim: SLE-15-SP4-Full-x86_64-GM-Media1 and vim-plugin-tlib-1.27-bp154.2.18.noarch issue
- Fixing bsc#1202414 VUL-1: CVE-2022-2819: vim: Heap-based Buffer Overflow in compile_lock_unlock()
- Fixing bsc#1202552 VUL-1: CVE-2022-2874: vim: NULL Pointer Dereference in generate_loadvar()
- Fixing bsc#1200270 VUL-1: CVE-2022-1968: vim: use after free in utf_ptr2char
- Fixing bsc#1200697 VUL-1: CVE-2022-2124: vim: out of bounds read in current_quote()
- Fixing bsc#1200698 VUL-1: CVE-2022-2125: vim: out of bounds read in get_lisp_indent()
- Fixing bsc#1200700 VUL-1: CVE-2022-2126: vim: out of bounds read in suggest_trie_walk()
- Fixing bsc#1200701 VUL-1: CVE-2022-2129: vim: out of bounds write in vim_regsub_both()
- Fixing bsc#1200732 VUL-1: CVE-2022-1720: vim: out of bounds read in grab_file_name()
- Fixing bsc#1201132 VUL-1: CVE-2022-2264: vim: out of bounds read in inc()
- Fixing bsc#1201133 VUL-1: CVE-2022-2284: vim: out of bounds read in utfc_ptr2len()
- Fixing bsc#1201134 VUL-1: CVE-2022-2285: vim: negative size passed to memmove() due to integer overflow
- Fixing bsc#1201135 VUL-1: CVE-2022-2286: vim: out of bounds read in ins_bytes()
- Fixing bsc#1201136 VUL-1: CVE-2022-2287: vim: out of bounds read in suggest_trie_walk()
- Fixing bsc#1201150 VUL-1: CVE-2022-2231: vim: null pointer dereference skipwhite()
- Fixing bsc#1201151 VUL-1: CVE-2022-2210: vim: out of bounds read in ml_append_int()
- Fixing bsc#1201152 VUL-1: CVE-2022-2208: vim: null pointer dereference in diff_check()
- Fixing bsc#1201153 VUL-1: CVE-2022-2207: vim: out of bounds read in ins_bs()
- Fixing bsc#1201154 VUL-1: CVE-2022-2257: vim: out of bounds read in msg_outtrans_special()
- Fixing bsc#1201155 VUL-1: CVE-2022-2206: vim: out of bounds read in msg_outtrans_attr()
- Fixing bsc#1201863 VUL-1: CVE-2022-2522: vim: out of bounds read via nested autocommand
- Fixing bsc#1202046 VUL-1: CVE-2022-2571: vim: Heap-based Buffer Overflow related to ins_comp_get_next_word_or_line()
- Fixing bsc#1202049 VUL-1: CVE-2022-2580: vim: Heap-based Buffer Overflow related to eval_string()
- Fixing bsc#1202050 VUL-1: CVE-2022-2581: vim: Out-of-bounds Read related to cstrchr()
- Fixing bsc#1202051 VUL-1: CVE-2022-2598: vim: Undefined Behavior for Input to API related to diff_mark_adjust_tp() and ex_diffgetput()
- Fixing bsc#1202420 VUL-1: CVE-2022-2817: vim: Use After Free in f_assert_fails()
- Fixing bsc#1202421 VUL-1: CVE-2022-2816: vim: Out-of-bounds Read in check_vim9_unlet()
- Fixing bsc#1202511 VUL-1: CVE-2022-2862: vim: use-after-free in compile_nested_function()
- Fixing bsc#1202512 VUL-1: CVE-2022-2849: vim: Invalid memory access related to mb_ptr2len()
- Fixing bsc#1202515 VUL-1: CVE-2022-2845: vim: Buffer Over-read related to display_dollar()
- Fixing bsc#1202599 VUL-1: CVE-2022-2889: vim: use-after-free in find_var_also_in_script() in evalvars.c
- Fixing bsc#1202687 VUL-1: CVE-2022-2923: vim: NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240
- Fixing bsc#1202689 VUL-1: CVE-2022-2946: vim: use after free in function vim_vsnprintf_typval
- Fixing bsc#1202862 VUL-1: CVE-2022-3016: vim: Use After Free in vim prior to 9.0.0285 Mon 12:00
- Fixing bsc#1191770 VUL-0: CVE-2021-3875: vim: heap-based buffer overflow
- Fixing bsc#1192167 VUL-0: CVE-2021-3903: vim: heap-based buffer overflow
- Fixing bsc#1192902 VUL-0: CVE-2021-3968: vim: vim is vulnerable to Heap-based Buffer Overflow
- Fixing bsc#1192903 VUL-0: CVE-2021-3973: vim: vim is vulnerable to Heap-based Buffer Overflow
- Fixing bsc#1192904 VUL-0: CVE-2021-3974: vim: vim is vulnerable to Use After Free
- Fixing bsc#1193466 VUL-1: CVE-2021-4069: vim: use-after-free in ex_open() in src/ex_docmd.c
- Fixing bsc#1193905 VUL-0: CVE-2021-4136: vim: vim is vulnerable to Heap-based Buffer Overflow
- Fixing bsc#1194093 VUL-1: CVE-2021-4166: vim: vim is vulnerable to Out-of-bounds Read
- Fixing bsc#1194216 VUL-1: CVE-2021-4193: vim: vulnerable to Out-of-bounds Read
- Fixing bsc#1194217 VUL-0: CVE-2021-4192: vim: vulnerable to Use After Free
- Fixing bsc#1194872 VUL-0: CVE-2022-0261: vim: Heap-based Buffer Overflow in vim prior to 8.2.
- Fixing bsc#1194885 VUL-0: CVE-2022-0213: vim: vim is vulnerable to Heap-based Buffer Overflow
- Fixing bsc#1195004 VUL-0: CVE-2022-0318: vim: Heap-based Buffer Overflow in vim prior to 8.2.
- Fixing bsc#1195203 VUL-0: CVE-2022-0359: vim: heap-based buffer overflow in init_ccline() in ex_getln.c
- Fixing bsc#1195354 VUL-0: CVE-2022-0407: vim: Heap-based Buffer Overflow in Conda vim prior to 8.2.
- Fixing bsc#1198596 VUL-0: CVE-2022-1381: vim: global heap buffer overflow in skip_range
- Fixing bsc#1199331 VUL-0: CVE-2022-1616: vim: Use after free in append_command
- Fixing bsc#1199333 VUL-0: CVE-2022-1619: vim: Heap-based Buffer Overflow in function cmdline_erase_chars
- Fixing bsc#1199334 VUL-0: CVE-2022-1620: vim: NULL Pointer Dereference in function vim_regexec_string
- Fixing bsc#1199747 VUL-0: CVE-2022-1796: vim: Use After in find_pattern_in_path
- Fixing bsc#1200010 VUL-0: CVE-2022-1897: vim: Out-of-bounds Write in vim
- Fixing bsc#1200011 VUL-0: CVE-2022-1898: vim: Use After Free in vim prior to 8.2
- Fixing bsc#1200012 VUL-0: CVE-2022-1927: vim: Buffer Over-read in vim prior to 8.2
- Fixing bsc#1070955 VUL-1: CVE-2017-17087: vim: Sets the group ownership of a .swp file to the editor's primary group, which allows local users to obtain sensitive information
- Fixing bsc#1194388 VUL-1: CVE-2022-0128: vim: vim is vulnerable to Out-of-bounds Read
- Fixing bsc#1195332 VUL-1: CVE-2022-0392: vim: Heap-based Buffer Overflow in vim prior to 8.2
- Fixing bsc#1196361 VUL-1: CVE-2022-0696: vim: NULL Pointer Dereference in vim prior to 8.2
- Fixing bsc#1198748 VUL-1: CVE-2022-1420: vim: Out-of-range Pointer Offset
- Fixing bsc#1199651 VUL-1: CVE-2022-1735: vim: heap buffer overflow
- Fixing bsc#1199655 VUL-1: CVE-2022-1733: vim: Heap-based Buffer Overflow in cindent.c
- Fixing bsc#1199693 VUL-1: CVE-2022-1771: vim: stack exhaustion in vim prior to 8.2.
- Fixing bsc#1199745 VUL-1: CVE-2022-1785: vim: Out-of-bounds Write
- Fixing bsc#1199936 VUL-1: CVE-2022-1851: vim: out of bounds read
- Fixing bsc#1195004 - (CVE-2022-0318) VUL-0: CVE-2022-0318: vim: Heap-based Buffer Overflow in vim prior to 8.2.
- Fixing bsc#1190570 CVE-2021-3796: vim: use-after-free in nv_replace() in normal.c
- Fixing bsc#1191893 CVE-2021-3872: vim: heap-based buffer overflow in win_redr_status() drawscreen.c
- Fixing bsc#1192481 CVE-2021-3927: vim: vim is vulnerable to Heap-based Buffer Overflow
- Fixing bsc#1192478 CVE-2021-3928: vim: vim is vulnerable to Stack-based Buffer Overflow
- Fixing bsc#1193294 CVE-2021-4019: vim: vim is vulnerable to Heap-based Buffer Overflow
- Fixing bsc#1193298 CVE-2021-3984: vim: illegal memory access when C-indenting could lead to Heap Buffer Overflow
- Fixing bsc#1190533 CVE-2021-3778: vim: Heap-based Buffer Overflow in regexp_nfa.c
- Fixing bsc#1194216 CVE-2021-4193: vim: vulnerable to Out-of-bounds Read
- Fixing bsc#1194556 CVE-2021-46059: vim: A Pointer Dereference vulnerability exists in Vim 8.2.3883 via the vim_regexec_multi function at regexp.c, which causes a denial of service.
- Fixing bsc#1195066 CVE-2022-0319: vim: Out-of-bounds Read in vim/vim prior to 8.2.
- Fixing bsc#1195126 CVE-2022-0351: vim: uncontrolled recursion in eval7()
- Fixing bsc#1195202 CVE-2022-0361: vim: Heap-based Buffer Overflow in vim prior to 8.2.
- Fixing bsc#1195356 CVE-2022-0413: vim: use after free in src/ex_cmds.c
Список пакетов
Image SLES12-SP5-Azure-BYOS
Image SLES12-SP5-Azure-Basic-On-Demand
Image SLES12-SP5-Azure-HPC-BYOS
Image SLES12-SP5-Azure-HPC-On-Demand
Image SLES12-SP5-Azure-SAP-BYOS
Image SLES12-SP5-Azure-SAP-On-Demand
Image SLES12-SP5-Azure-Standard-On-Demand
Image SLES12-SP5-EC2-BYOS
Image SLES12-SP5-EC2-ECS-On-Demand
Image SLES12-SP5-EC2-On-Demand
Image SLES12-SP5-EC2-SAP-BYOS
Image SLES12-SP5-EC2-SAP-On-Demand
Image SLES12-SP5-GCE-BYOS
Image SLES12-SP5-GCE-On-Demand
Image SLES12-SP5-GCE-SAP-BYOS
Image SLES12-SP5-GCE-SAP-On-Demand
Image SLES12-SP5-SAP-Azure-LI-BYOS-Production
Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 9
Ссылки
- Link for SUSE-SU-2022:4619-1
- E-Mail link for SUSE-SU-2022:4619-1
- SUSE Security Ratings
- SUSE Bug 1070955
- SUSE Bug 1173256
- SUSE Bug 1174564
- SUSE Bug 1176549
- SUSE Bug 1182324
- SUSE Bug 1190533
- SUSE Bug 1190570
- SUSE Bug 1191770
- SUSE Bug 1191893
- SUSE Bug 1192167
- SUSE Bug 1192478
- SUSE Bug 1192481
- SUSE Bug 1192902
- SUSE Bug 1192903
- SUSE Bug 1192904
- SUSE Bug 1193294
- SUSE Bug 1193298
Описание
Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.
Затронутые продукты
Ссылки
- CVE-2009-0316
- SUSE Bug 470100
Описание
vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of arbitrary code if a file with a specially crafted modeline is opened.
Затронутые продукты
Ссылки
- CVE-2016-1248
- SUSE Bug 1010685
- SUSE Bug 1173534
Описание
fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned by root:users mode 0640, a different vulnerability than CVE-2017-1000382.
Затронутые продукты
Ссылки
- CVE-2017-17087
- SUSE Bug 1065958
- SUSE Bug 1070955
Описание
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
Затронутые продукты
Ссылки
- CVE-2017-5953
- SUSE Bug 1024724
- SUSE Bug 1123143
- SUSE Bug 1173534
Описание
An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
Затронутые продукты
Ссылки
- CVE-2017-6349
- SUSE Bug 1027057
Описание
An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
Затронутые продукты
Ссылки
- CVE-2017-6350
- SUSE Bug 1027053
Описание
vim is vulnerable to Heap-based Buffer Overflow
Затронутые продукты
Ссылки
- CVE-2021-3778
- SUSE Bug 1190533
Описание
vim is vulnerable to Use After Free
Затронутые продукты
Ссылки
- CVE-2021-3796
- SUSE Bug 1190570
Описание
vim is vulnerable to Heap-based Buffer Overflow
Затронутые продукты
Ссылки
- CVE-2021-3872
- SUSE Bug 1191893
Описание
vim is vulnerable to Heap-based Buffer Overflow
Затронутые продукты
Ссылки
- CVE-2021-3875
- SUSE Bug 1191770
- SUSE Bug 1208651
Описание
vim is vulnerable to Heap-based Buffer Overflow
Затронутые продукты
Ссылки
- CVE-2021-3903
- SUSE Bug 1192167
Описание
vim is vulnerable to Heap-based Buffer Overflow
Затронутые продукты
Ссылки
- CVE-2021-3927
- SUSE Bug 1192481
Описание
vim is vulnerable to Use of Uninitialized Variable
Затронутые продукты
Ссылки
- CVE-2021-3928
- SUSE Bug 1192478
Описание
vim is vulnerable to Heap-based Buffer Overflow
Затронутые продукты
Ссылки
- CVE-2021-3968
- SUSE Bug 1192902
- SUSE Bug 1208308
- SUSE Bug 1208649
- SUSE Bug 1208651
Описание
vim is vulnerable to Heap-based Buffer Overflow
Затронутые продукты
Ссылки
- CVE-2021-3973
- SUSE Bug 1192903
- SUSE Bug 1208308
- SUSE Bug 1208649
- SUSE Bug 1208651
Описание
vim is vulnerable to Use After Free
Затронутые продукты
Ссылки
- CVE-2021-3974
- SUSE Bug 1192904
- SUSE Bug 1206818
- SUSE Bug 1208308
- SUSE Bug 1208651
Описание
vim is vulnerable to Heap-based Buffer Overflow
Затронутые продукты
Ссылки
- CVE-2021-3984
- SUSE Bug 1193298
Описание
vim is vulnerable to Heap-based Buffer Overflow
Затронутые продукты
Ссылки
- CVE-2021-4019
- SUSE Bug 1193294
Описание
vim is vulnerable to Use After Free
Затронутые продукты
Ссылки
- CVE-2021-4069
- SUSE Bug 1193466
Описание
vim is vulnerable to Heap-based Buffer Overflow
Затронутые продукты
Ссылки
- CVE-2021-4136
- SUSE Bug 1193905
- SUSE Bug 1208308
- SUSE Bug 1208649
- SUSE Bug 1208651
Описание
vim is vulnerable to Out-of-bounds Read
Затронутые продукты
Ссылки
- CVE-2021-4166
- SUSE Bug 1194093
Описание
vim is vulnerable to Use After Free
Затронутые продукты
Ссылки
- CVE-2021-4192
- SUSE Bug 1194217
Описание
vim is vulnerable to Out-of-bounds Read
Затронутые продукты
Ссылки
- CVE-2021-4193
- SUSE Bug 1194216
Описание
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Затронутые продукты
Ссылки
- CVE-2021-46059
- SUSE Bug 1194556
Описание
vim is vulnerable to Out-of-bounds Read
Затронутые продукты
Ссылки
- CVE-2022-0128
- SUSE Bug 1194388
Описание
vim is vulnerable to Heap-based Buffer Overflow
Затронутые продукты
Ссылки
- CVE-2022-0213
- SUSE Bug 1194885
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-0261
- SUSE Bug 1194872
Описание
Heap-based Buffer Overflow in vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-0318
- SUSE Bug 1195004
Описание
Out-of-bounds Read in vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-0319
- SUSE Bug 1195066
Описание
Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-0351
- SUSE Bug 1195126
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-0359
- SUSE Bug 1195203
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-0361
- SUSE Bug 1195202
Описание
Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-0392
- SUSE Bug 1195332
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-0407
- SUSE Bug 1195354
- SUSE Bug 1208308
- SUSE Bug 1208649
- SUSE Bug 1208651
Описание
Use After Free in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-0413
- SUSE Bug 1195356
- SUSE Bug 1208308
- SUSE Bug 1208651
Описание
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
Затронутые продукты
Ссылки
- CVE-2022-0696
- SUSE Bug 1196361
- SUSE Bug 1205395
Описание
global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
Затронутые продукты
Ссылки
- CVE-2022-1381
- SUSE Bug 1198596
Описание
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
Затронутые продукты
Ссылки
- CVE-2022-1420
- SUSE Bug 1198748
Описание
Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
Затронутые продукты
Ссылки
- CVE-2022-1616
- SUSE Bug 1199331
Описание
Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
Затронутые продукты
Ссылки
- CVE-2022-1619
- SUSE Bug 1199333
Описание
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vim prior to 8.2.4901. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 allows attackers to cause a denial of service (application crash) via a crafted input.
Затронутые продукты
Ссылки
- CVE-2022-1620
- SUSE Bug 1199334
Описание
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
Затронутые продукты
Ссылки
- CVE-2022-1720
- SUSE Bug 1200732
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.
Затронутые продукты
Ссылки
- CVE-2022-1733
- SUSE Bug 1199655
Описание
Classic Buffer Overflow in GitHub repository vim/vim prior to 8.2.4969.
Затронутые продукты
Ссылки
- CVE-2022-1735
- SUSE Bug 1199651
Описание
Uncontrolled Recursion in GitHub repository vim/vim prior to 8.2.4975.
Затронутые продукты
Ссылки
- CVE-2022-1771
- SUSE Bug 1199693
Описание
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.
Затронутые продукты
Ссылки
- CVE-2022-1785
- SUSE Bug 1199745
Описание
Use After Free in GitHub repository vim/vim prior to 8.2.4979.
Затронутые продукты
Ссылки
- CVE-2022-1796
- SUSE Bug 1199747
Описание
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-1851
- SUSE Bug 1199936
Описание
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-1897
- SUSE Bug 1200010
Описание
Use After Free in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-1898
- SUSE Bug 1200011
Описание
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-1927
- SUSE Bug 1200012
Описание
Use After Free in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-1968
- SUSE Bug 1200270
Описание
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-2124
- SUSE Bug 1200697
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-2125
- SUSE Bug 1200698
- SUSE Bug 1205395
Описание
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-2126
- SUSE Bug 1200700
Описание
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-2129
- SUSE Bug 1200701
Описание
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-2175
- SUSE Bug 1200904
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-2182
- SUSE Bug 1200903
Описание
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-2183
- SUSE Bug 1200902
Описание
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-2206
- SUSE Bug 1201155
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-2207
- SUSE Bug 1201153
Описание
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
Затронутые продукты
Ссылки
- CVE-2022-2208
- SUSE Bug 1201152
Описание
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-2210
- SUSE Bug 1201151
Описание
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.
Затронутые продукты
Ссылки
- CVE-2022-2231
- SUSE Bug 1201150
Описание
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
Затронутые продукты
Ссылки
- CVE-2022-2257
- SUSE Bug 1201154
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
Затронутые продукты
Ссылки
- CVE-2022-2264
- SUSE Bug 1201132
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
Затронутые продукты
Ссылки
- CVE-2022-2284
- SUSE Bug 1201133
Описание
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
Затронутые продукты
Ссылки
- CVE-2022-2285
- SUSE Bug 1201134
Описание
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
Затронутые продукты
Ссылки
- CVE-2022-2286
- SUSE Bug 1201135
Описание
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
Затронутые продукты
Ссылки
- CVE-2022-2287
- SUSE Bug 1201136
Описание
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
Затронутые продукты
Ссылки
- CVE-2022-2304
- SUSE Bug 1201249
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044.
Затронутые продукты
Ссылки
- CVE-2022-2343
- SUSE Bug 1201356
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.
Затронутые продукты
Ссылки
- CVE-2022-2344
- SUSE Bug 1201359
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0046.
Затронутые продукты
Ссылки
- CVE-2022-2345
- SUSE Bug 1201363
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0061.
Затронутые продукты
Ссылки
- CVE-2022-2522
- SUSE Bug 1201863
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101.
Затронутые продукты
Ссылки
- CVE-2022-2571
- SUSE Bug 1202046
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0102.
Затронутые продукты
Ссылки
- CVE-2022-2580
- SUSE Bug 1202049
Описание
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104.
Затронутые продукты
Ссылки
- CVE-2022-2581
- SUSE Bug 1202050
Описание
Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100.
Затронутые продукты
Ссылки
- CVE-2022-2598
- SUSE Bug 1202051
Описание
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.
Затронутые продукты
Ссылки
- CVE-2022-2816
- SUSE Bug 1202421
- SUSE Bug 1203576
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0213.
Затронутые продукты
Ссылки
- CVE-2022-2817
- SUSE Bug 1202420
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.
Затронутые продукты
Ссылки
- CVE-2022-2819
- SUSE Bug 1202414
- SUSE Bug 1203576
Описание
Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.
Затронутые продукты
Ссылки
- CVE-2022-2845
- SUSE Bug 1202515
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.
Затронутые продукты
Ссылки
- CVE-2022-2849
- SUSE Bug 1202512
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0221.
Затронутые продукты
Ссылки
- CVE-2022-2862
- SUSE Bug 1202511
Описание
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0224.
Затронутые продукты
Ссылки
- CVE-2022-2874
- SUSE Bug 1202552
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0225.
Затронутые продукты
Ссылки
- CVE-2022-2889
- SUSE Bug 1202599
Описание
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240.
Затронутые продукты
Ссылки
- CVE-2022-2923
- SUSE Bug 1202687
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0246.
Затронутые продукты
Ссылки
- CVE-2022-2946
- SUSE Bug 1202689
Описание
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259.
Затронутые продукты
Ссылки
- CVE-2022-2980
- SUSE Bug 1203155
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0260.
Затронутые продукты
Ссылки
- CVE-2022-2982
- SUSE Bug 1203152
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0286.
Затронутые продукты
Ссылки
- CVE-2022-3016
- SUSE Bug 1202862
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0322.
Затронутые продукты
Ссылки
- CVE-2022-3037
- SUSE Bug 1202962
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0360.
Затронутые продукты
Ссылки
- CVE-2022-3099
- SUSE Bug 1203110
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0389.
Затронутые продукты
Ссылки
- CVE-2022-3134
- SUSE Bug 1203194
Описание
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0404.
Затронутые продукты
Ссылки
- CVE-2022-3153
- SUSE Bug 1203272
Описание
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
Затронутые продукты
Ссылки
- CVE-2022-3234
- SUSE Bug 1203508
- SUSE Bug 1206240
- SUSE Bug 1208002
- SUSE Bug 1208308
- SUSE Bug 1208651
- SUSE Bug 1209329
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0490.
Затронутые продукты
Ссылки
- CVE-2022-3235
- SUSE Bug 1203509
Описание
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.
Затронутые продукты
Ссылки
- CVE-2022-3278
- SUSE Bug 1203799
Описание
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
Затронутые продукты
Ссылки
- CVE-2022-3296
- SUSE Bug 1203796
- SUSE Bug 1205395
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0579.
Затронутые продукты
Ссылки
- CVE-2022-3297
- SUSE Bug 1203797
Описание
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
Затронутые продукты
Ссылки
- CVE-2022-3324
- SUSE Bug 1203820
- SUSE Bug 1205395
- SUSE Bug 1206240
Описание
Use After Free in GitHub repository vim/vim prior to 9.0.0614.
Затронутые продукты
Ссылки
- CVE-2022-3352
- SUSE Bug 1203924
Описание
A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version 9.0.0805 is able to address this issue. The name of the patch is d0fab10ed2a86698937e3c3fed2f10bd9bb5e731. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-212324.
Затронутые продукты
Ссылки
- CVE-2022-3705
- SUSE Bug 1204779