Количество 21
Количество 21
BDU:2026-05722
Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды
ROS-20260524-73-0037
Уязвимость vim
CVE-2026-34982
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
CVE-2026-34982
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
CVE-2026-34982
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue.
CVE-2026-34982
Vim modeline bypass via various options affects Vim < 9.2.0276
CVE-2026-34982
Vim is an open source, command line text editor. Prior to version 9.2. ...
RLSA-2026:19224
Important: vim security update
RLSA-2026:19073
Important: vim security update
RLSA-2026:11510
Important: vim security update
RLSA-2026:11509
Important: vim security update
RLSA-2026:11389
Important: vim security update
ELSA-2026-19224
ELSA-2026-19224: vim security update (IMPORTANT)
ELSA-2026-19073
ELSA-2026-19073: vim security update (IMPORTANT)
ELSA-2026-11510
ELSA-2026-11510: vim security update (IMPORTANT)
ELSA-2026-11509
ELSA-2026-11509: vim security update (IMPORTANT)
ELSA-2026-11389
ELSA-2026-11389: vim security update (IMPORTANT)
openSUSE-SU-2026:20540-1
Security update for vim
SUSE-SU-2026:1607-1
Security update for vim
SUSE-SU-2026:1387-1
Security update for vim
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-05722 Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды | CVSS3: 8.2 | 0% Низкий | 4 месяца назад | |
ROS-20260524-73-0037 Уязвимость vim | CVSS3: 8.2 | 0% Низкий | 2 месяца назад | |
CVE-2026-34982 Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue. | CVSS3: 8.2 | 0% Низкий | 4 месяца назад | |
CVE-2026-34982 Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue. | CVSS3: 8.2 | 0% Низкий | 4 месяца назад | |
CVE-2026-34982 Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a modeline to be executed. Additionally, the `mapset()` function lacks a `check_secure()` call, allowing it to be abused from sandboxed expressions. Commit 9.2.0276 fixes the issue. | CVSS3: 8.2 | 0% Низкий | 4 месяца назад | |
CVE-2026-34982 Vim modeline bypass via various options affects Vim < 9.2.0276 | CVSS3: 8.2 | 0% Низкий | 4 месяца назад | |
CVE-2026-34982 Vim is an open source, command line text editor. Prior to version 9.2. ... | CVSS3: 8.2 | 0% Низкий | 4 месяца назад | |
RLSA-2026:19224 Important: vim security update | 0% Низкий | 2 месяца назад | ||
RLSA-2026:19073 Important: vim security update | 0% Низкий | 2 месяца назад | ||
RLSA-2026:11510 Important: vim security update | 0% Низкий | 3 месяца назад | ||
RLSA-2026:11509 Important: vim security update | 0% Низкий | 3 месяца назад | ||
RLSA-2026:11389 Important: vim security update | 0% Низкий | 3 месяца назад | ||
ELSA-2026-19224 ELSA-2026-19224: vim security update (IMPORTANT) | 0% Низкий | около 2 месяцев назад | ||
ELSA-2026-19073 ELSA-2026-19073: vim security update (IMPORTANT) | 0% Низкий | 25 дней назад | ||
ELSA-2026-11510 ELSA-2026-11510: vim security update (IMPORTANT) | 0% Низкий | 3 месяца назад | ||
ELSA-2026-11509 ELSA-2026-11509: vim security update (IMPORTANT) | 0% Низкий | 3 месяца назад | ||
ELSA-2026-11389 ELSA-2026-11389: vim security update (IMPORTANT) | 0% Низкий | 3 месяца назад | ||
openSUSE-SU-2026:20540-1 Security update for vim | 4 месяца назад | |||
SUSE-SU-2026:1607-1 Security update for vim | 3 месяца назад | |||
SUSE-SU-2026:1387-1 Security update for vim | 4 месяца назад |
Уязвимостей на страницу