Количество 13
Количество 13
CVE-2026-41411
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user.
CVE-2026-41411
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user.
CVE-2026-41411
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user.
CVE-2026-41411
Vim: Command injection via backtick expansion in tag filenames
CVE-2026-41411
Vim is an open source, command line text editor. Prior to 9.2.0357, A ...
RLSA-2026:28553
Moderate: vim security update
RLSA-2026:28210
Moderate: vim security update
RLSA-2026:28209
Moderate: vim security update
ELSA-2026-28553
ELSA-2026-28553: vim security update (MODERATE)
ELSA-2026-28210
ELSA-2026-28210: vim security update (MODERATE)
ELSA-2026-28209
ELSA-2026-28209: vim security update (MODERATE)
BDU:2026-09836
Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю, действующему удаленно, выполнить произвольные команды
ROS-20260629-73-0020
Уязвимость vim
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-41411 Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user. | CVSS3: 6.6 | 1% Низкий | 3 месяца назад | |
CVE-2026-41411 Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user. | CVSS3: 7.3 | 1% Низкий | 3 месяца назад | |
CVE-2026-41411 Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's tag file processing. When resolving a tag, the filename field from the tags file is passed through wildcard expansion to resolve environment variables and wildcards. If the filename field contains backtick syntax (e.g., `command`), Vim executes the embedded command via the system shell with the full privileges of the running user. | CVSS3: 6.6 | 1% Низкий | 3 месяца назад | |
CVE-2026-41411 Vim: Command injection via backtick expansion in tag filenames | CVSS3: 6.6 | 1% Низкий | 3 месяца назад | |
CVE-2026-41411 Vim is an open source, command line text editor. Prior to 9.2.0357, A ... | CVSS3: 6.6 | 1% Низкий | 3 месяца назад | |
RLSA-2026:28553 Moderate: vim security update | 1% Низкий | около 1 месяца назад | ||
RLSA-2026:28210 Moderate: vim security update | 1% Низкий | около 1 месяца назад | ||
RLSA-2026:28209 Moderate: vim security update | 1% Низкий | около 1 месяца назад | ||
ELSA-2026-28553 ELSA-2026-28553: vim security update (MODERATE) | 1% Низкий | около 1 месяца назад | ||
ELSA-2026-28210 ELSA-2026-28210: vim security update (MODERATE) | 1% Низкий | 10 дней назад | ||
ELSA-2026-28209 ELSA-2026-28209: vim security update (MODERATE) | 1% Низкий | около 1 месяца назад | ||
BDU:2026-09836 Уязвимость текстового редактора vim, связанная с непринятием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю, действующему удаленно, выполнить произвольные команды | CVSS3: 6.6 | 1% Низкий | 3 месяца назад | |
ROS-20260629-73-0020 Уязвимость vim | CVSS3: 6.6 | 1% Низкий | около 1 месяца назад |
Уязвимостей на страницу