Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

fstec логотип

BDU:2026-14513

3 месяца назад

Уязвимость механизма автодополнения PHP-кода Python omni-completion модуля runtime/autoload/phpcomplete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2026-59856

2 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-59856

2 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-59856

2 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2026-59856

2 месяца назад

Vim: Arbitrary Code Execution via PHP Omni-Completion

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-59856

2 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0736, th ...

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260819-80-0037

30 дней назад

Уязвимость vim

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260819-73-0037

30 дней назад

Уязвимость vim

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21374-1

2 месяца назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3458-1

около 2 месяцев назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3271-1

около 2 месяцев назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3237-1

около 2 месяцев назад

Security update for vim

EPSS: Низкий
rocky логотип

RLSA-2026:48650

около 2 месяцев назад

Important: vim security update

EPSS: Низкий
rocky логотип

RLSA-2026:47982

около 2 месяцев назад

Important: vim security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-48650

около 2 месяцев назад

ELSA-2026-48650: vim security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-47982

около 2 месяцев назад

ELSA-2026-47982: vim security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-14513

Уязвимость механизма автодополнения PHP-кода Python omni-completion модуля runtime/autoload/phpcomplete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-59856

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 7.8
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-59856

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 5.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-59856

Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/phpcomplete.vim interpolates a class or trait name, taken from the contents of the edited buffer, into a search() pattern that is run via win_execute() without escaping. A name containing a single quote can terminate the search() string argument early, and because the bar is honored as an Ex command separator, the remainder of the name is run as Ex commands; via the :! command this allows arbitrary operating-system command execution when a victim opens a crafted PHP file and invokes omni-completion. This issue is fixed in version 9.2.0736.

CVSS3: 7.8
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-59856

Vim: Arbitrary Code Execution via PHP Omni-Completion

CVSS3: 7.8
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-59856

Vim is an open source, command line text editor. Prior to 9.2.0736, th ...

CVSS3: 7.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260819-80-0037

Уязвимость vim

CVSS3: 7.8
0%
Низкий
30 дней назад
redos логотип
ROS-20260819-73-0037

Уязвимость vim

CVSS3: 7.8
0%
Низкий
30 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21374-1

Security update for vim

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3458-1

Security update for vim

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3271-1

Security update for vim

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3237-1

Security update for vim

около 2 месяцев назад
rocky логотип
RLSA-2026:48650

Important: vim security update

около 2 месяцев назад
rocky логотип
RLSA-2026:47982

Important: vim security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-48650

ELSA-2026-48650: vim security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-47982

ELSA-2026-47982: vim security update (IMPORTANT)

около 2 месяцев назад

Уязвимостей на страницу