Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

ubuntu логотип

CVE-2026-55892

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2026-55892

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-55892

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2026-55892

3 месяца назад

Vim: Out-of-bounds Write in Spell File Prefix Dump

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2026-55892

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0662, th ...

CVSS3: 5.5
EPSS: Низкий
redos логотип

ROS-20260819-80-0028

30 дней назад

Уязвимость vim

CVSS3: 5.5
EPSS: Низкий
redos логотип

ROS-20260819-73-0028

30 дней назад

Уязвимость vim

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2026-14508

3 месяца назад

Уязвимость функции dump_prefixes() файла src/spell.c текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
EPSS: Низкий
rocky логотип

RLSA-2026:66348

7 дней назад

Important: vim security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-66348-0

8 дней назад

ELSA-2026-66348-0: vim security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:66366

6 дней назад

Important: vim security update

EPSS: Низкий
rocky логотип

RLSA-2026:66336

6 дней назад

Important: vim security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-66366-0

8 дней назад

ELSA-2026-66366-0: vim security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-66336-0

8 дней назад

ELSA-2026-66336-0: vim security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-55892

Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.

CVSS3: 5.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-55892

Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.

CVSS3: 5.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-55892

Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a spell-file prefix trie iteratively with a depth counter while dumping the prefixes that apply to a word. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (prefix[], arridx[], curi[]). A crafted .spl file, loaded when the user dumps the word list, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0662.

CVSS3: 5.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-55892

Vim: Out-of-bounds Write in Spell File Prefix Dump

CVSS3: 5.5
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-55892

Vim is an open source, command line text editor. Prior to 9.2.0662, th ...

CVSS3: 5.5
0%
Низкий
3 месяца назад
redos логотип
ROS-20260819-80-0028

Уязвимость vim

CVSS3: 5.5
0%
Низкий
30 дней назад
redos логотип
ROS-20260819-73-0028

Уязвимость vim

CVSS3: 5.5
0%
Низкий
30 дней назад
fstec логотип
BDU:2026-14508

Уязвимость функции dump_prefixes() файла src/spell.c текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.5
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:66348

Important: vim security update

7 дней назад
oracle-oval логотип
ELSA-2026-66348-0

ELSA-2026-66348-0: vim security update (IMPORTANT)

8 дней назад
rocky логотип
RLSA-2026:66366

Important: vim security update

6 дней назад
rocky логотип
RLSA-2026:66336

Important: vim security update

6 дней назад
oracle-oval логотип
ELSA-2026-66366-0

ELSA-2026-66366-0: vim security update (IMPORTANT)

8 дней назад
oracle-oval логотип
ELSA-2026-66336-0

ELSA-2026-66336-0: vim security update (IMPORTANT)

8 дней назад

Уязвимостей на страницу