Количество 17
Количество 17
CVE-2026-59858
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.
CVE-2026-59858
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.
CVE-2026-59858
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.
CVE-2026-59858
Vim is an open source, command line text editor. Prior to 9.2.0735, th ...
ROS-20260819-80-0036
Уязвимость vim
ROS-20260819-73-0036
Уязвимость vim
BDU:2026-14504
Уязвимость механизма автодополнения C omni-completion модуля runtime/autoload/ccomplete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код
openSUSE-SU-2026:21374-1
Security update for vim
SUSE-SU-2026:3458-1
Security update for vim
SUSE-SU-2026:3271-1
Security update for vim
SUSE-SU-2026:3237-1
Security update for vim
RLSA-2026:48703
Important: vim security update
ELSA-2026-48703
ELSA-2026-48703: vim security update (IMPORTANT)
RLSA-2026:48650
Important: vim security update
RLSA-2026:47982
Important: vim security update
ELSA-2026-48650
ELSA-2026-48650: vim security update (IMPORTANT)
ELSA-2026-47982
ELSA-2026-47982: vim security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59858 Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-59858 Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-59858 Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-59858 Vim is an open source, command line text editor. Prior to 9.2.0735, th ... | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
ROS-20260819-80-0036 Уязвимость vim | CVSS3: 7.8 | 0% Низкий | 30 дней назад | |
ROS-20260819-73-0036 Уязвимость vim | CVSS3: 7.8 | 0% Низкий | 30 дней назад | |
BDU:2026-14504 Уязвимость механизма автодополнения C omni-completion модуля runtime/autoload/ccomplete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21374-1 Security update for vim | 2 месяца назад | |||
SUSE-SU-2026:3458-1 Security update for vim | около 2 месяцев назад | |||
SUSE-SU-2026:3271-1 Security update for vim | около 2 месяцев назад | |||
SUSE-SU-2026:3237-1 Security update for vim | около 2 месяцев назад | |||
RLSA-2026:48703 Important: vim security update | около 2 месяцев назад | |||
ELSA-2026-48703 ELSA-2026-48703: vim security update (IMPORTANT) | около 2 месяцев назад | |||
RLSA-2026:48650 Important: vim security update | около 2 месяцев назад | |||
RLSA-2026:47982 Important: vim security update | около 2 месяцев назад | |||
ELSA-2026-48650 ELSA-2026-48650: vim security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-47982 ELSA-2026-47982: vim security update (IMPORTANT) | около 2 месяцев назад |
Уязвимостей на страницу