Количество 34
Количество 34
RLSA-2026:8259
Important: vim security update
RLSA-2026:7711
Important: vim security update
RLSA-2026:6915
Important: vim security update
ELSA-2026-8259
ELSA-2026-8259: vim security update (IMPORTANT)
ELSA-2026-7711
ELSA-2026-7711: vim security update (IMPORTANT)
ELSA-2026-6915
ELSA-2026-6915: vim security update (IMPORTANT)
ELSA-2026-6617
ELSA-2026-6617: vim security update (IMPORTANT)
SUSE-SU-2026:1095-1
Security update for vim
SUSE-SU-2026:1051-1
Security update for vim
SUSE-SU-2026:0910-1
Security update for vim
CVE-2026-28417
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.
CVE-2026-28417
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.
CVE-2026-28417
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.
CVE-2026-28417
Vim has OS Command Injection in netrw
CVE-2026-28417
Vim is an open source, command line text editor. Prior to version 9.2. ...
BDU:2026-02589
Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды
openSUSE-SU-2026:20403-1
Security update for vim
CVE-2026-33412
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202.
CVE-2026-33412
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202.
CVE-2026-33412
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:8259 Important: vim security update | 4 месяца назад | |||
RLSA-2026:7711 Important: vim security update | 4 месяца назад | |||
RLSA-2026:6915 Important: vim security update | 4 месяца назад | |||
ELSA-2026-8259 ELSA-2026-8259: vim security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2026-7711 ELSA-2026-7711: vim security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2026-6915 ELSA-2026-6915: vim security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2026-6617 ELSA-2026-6617: vim security update (IMPORTANT) | 3 месяца назад | |||
SUSE-SU-2026:1095-1 Security update for vim | 4 месяца назад | |||
SUSE-SU-2026:1051-1 Security update for vim | 4 месяца назад | |||
SUSE-SU-2026:0910-1 Security update for vim | 4 месяца назад | |||
CVE-2026-28417 Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue. | CVSS3: 4.4 | 1% Низкий | 5 месяцев назад | |
CVE-2026-28417 Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue. | CVSS3: 4.4 | 1% Низкий | 5 месяцев назад | |
CVE-2026-28417 Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue. | CVSS3: 4.4 | 1% Низкий | 5 месяцев назад | |
CVE-2026-28417 Vim has OS Command Injection in netrw | CVSS3: 4.4 | 1% Низкий | 5 месяцев назад | |
CVE-2026-28417 Vim is an open source, command line text editor. Prior to version 9.2. ... | CVSS3: 4.4 | 1% Низкий | 5 месяцев назад | |
BDU:2026-02589 Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды | CVSS3: 7.8 | 1% Низкий | 5 месяцев назад | |
openSUSE-SU-2026:20403-1 Security update for vim | 4 месяца назад | |||
CVE-2026-33412 Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202. | CVSS3: 5.6 | 1% Низкий | 4 месяца назад | |
CVE-2026-33412 Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202. | CVSS3: 7.3 | 1% Низкий | 4 месяца назад | |
CVE-2026-33412 Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to glob(), an attacker may be able to execute arbitrary shell commands. This vulnerability depends on the user's 'shell' setting. This issue has been patched in version 9.2.0202. | CVSS3: 5.6 | 1% Низкий | 4 месяца назад |
Уязвимостей на страницу