Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-42307

Опубликовано: 08 мая 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 4.4

Описание

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

РелизСтатусПримечание
devel

needs-triage

esm-infra-legacy/trusty

released

2:7.4.052-1ubuntu3.1+esm26
esm-infra-legacy/xenial

released

2:7.4.1689-3ubuntu1.5+esm32
esm-infra/bionic

released

2:8.0.1453-1ubuntu1.13+esm17
esm-infra/focal

released

2:8.1.2269-1ubuntu5.32+esm5
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

2:8.2.3995-1ubuntu2.30
noble

released

2:9.1.0016-1ubuntu7.14
questing

released

2:9.1.0967-1ubuntu6.5
resolute

released

2:9.1.2141-1ubuntu4.2

Показывать по

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
redhat
3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

CVSS3: 4.4
nvd
3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists in the netrw standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the sftp:// or file:// protocol handlers), an attacker can execute arbitrary shell commands with the privileges of the Vim process. This issue has been patched in version 9.2.0383.

CVSS3: 4.4
debian
3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2. ...

CVSS3: 4.4
fstec
3 месяца назад

Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольные команды

CVSS3: 4.4
redos
около 1 месяца назад

Уязвимость vim

4.4 Medium

CVSS3