Количество 11
Количество 11
BDU:2026-06512
Уязвимость функции :find текстового редактора vim, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании
ROS-20260626-73-0022
Уязвимость vim
CVE-2026-44656
Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435.
CVE-2026-44656
Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435.
CVE-2026-44656
Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435.
CVE-2026-44656
Vim: OS Command Injection via 'path' completion
CVE-2026-44656
Vim is an open source, command line text editor. Prior to version 9.2. ...
SUSE-SU-2026:2236-1
Security update for vim
SUSE-SU-2026:2233-1
Security update for vim
openSUSE-SU-2026:20828-1
Security update for vim
SUSE-SU-2026:2313-1
Security update for vim
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-06512 Уязвимость функции :find текстового редактора vim, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании | CVSS3: 7.8 | 1% Низкий | 3 месяца назад | |
ROS-20260626-73-0022 Уязвимость vim | CVSS3: 7.8 | 1% Низкий | около 1 месяца назад | |
CVE-2026-44656 Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435. | CVSS3: 5.3 | 1% Низкий | 3 месяца назад | |
CVE-2026-44656 Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435. | CVSS3: 5.3 | 1% Низкий | 3 месяца назад | |
CVE-2026-44656 Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435. | CVSS3: 5.3 | 1% Низкий | 3 месяца назад | |
CVE-2026-44656 Vim: OS Command Injection via 'path' completion | 1% Низкий | 3 месяца назад | ||
CVE-2026-44656 Vim is an open source, command line text editor. Prior to version 9.2. ... | CVSS3: 5.3 | 1% Низкий | 3 месяца назад | |
SUSE-SU-2026:2236-1 Security update for vim | 2 месяца назад | |||
SUSE-SU-2026:2233-1 Security update for vim | 2 месяца назад | |||
openSUSE-SU-2026:20828-1 Security update for vim | 2 месяца назад | |||
SUSE-SU-2026:2313-1 Security update for vim | около 2 месяцев назад |
Уязвимостей на страницу