Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-34714

Опубликовано: 30 мар. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.2

Описание

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

РелизСтатусПримечание
devel

not-affected

2:9.1.2141-1ubuntu4
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

not-affected

code not present
upstream

released

9.2.0272

Показывать по

EPSS

Процентиль: 45%
0.00588
Низкий

9.2 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.6
redhat
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 9.2
nvd
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 8.5
msrc
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

CVSS3: 9.2
debian
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upo ...

CVSS3: 9.2
github
4 месяца назад

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

EPSS

Процентиль: 45%
0.00588
Низкий

9.2 Critical

CVSS3