Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

ubuntu логотип

CVE-2026-55895

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-55895

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-55895

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2026-55895

3 месяца назад

Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-55895

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0663, a ...

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260819-80-0029

30 дней назад

Уязвимость vim

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260819-73-0029

30 дней назад

Уязвимость vim

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2026-14507

3 месяца назад

Уязвимость функции NetrwLocalRmFile() модуля runtime/pack/dist/opt/netrw/autoload/netrw.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-55895

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.

CVSS3: 7.8
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-55895

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.

CVSS3: 7.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-55895

Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when deleting a local file from the browser. A filename derived from the buffer's directory listing is interpolated into an Ex command line passed to :execute with only the backslash character escaped, allowing a crafted filename containing a bar (|) to terminate the intended command and execute arbitrary Vimscript, including shell commands via :call system() and :!. This vulnerability is fixed in 9.2.0663.

CVSS3: 7.8
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-55895

Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename

CVSS3: 7.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-55895

Vim is an open source, command line text editor. Prior to 9.2.0663, a ...

CVSS3: 7.8
0%
Низкий
3 месяца назад
redos логотип
ROS-20260819-80-0029

Уязвимость vim

CVSS3: 7.8
0%
Низкий
30 дней назад
redos логотип
ROS-20260819-73-0029

Уязвимость vim

CVSS3: 7.8
0%
Низкий
30 дней назад
fstec логотип
BDU:2026-14507

Уязвимость функции NetrwLocalRmFile() модуля runtime/pack/dist/opt/netrw/autoload/netrw.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу