Количество 17
Количество 17
CVE-2026-59857
Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725.
CVE-2026-59857
Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725.
CVE-2026-59857
Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725.
CVE-2026-59857
Vim is an open source, command line text editor. Prior to 9.2.0725, th ...
ROS-20260819-80-0038
Уязвимость vim
ROS-20260819-73-0038
Уязвимость vim
BDU:2026-14505
Уязвимость функции spell_soundfold_sal() файла src/spell.c текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании
openSUSE-SU-2026:21374-1
Security update for vim
SUSE-SU-2026:3458-1
Security update for vim
SUSE-SU-2026:3271-1
Security update for vim
SUSE-SU-2026:3237-1
Security update for vim
RLSA-2026:66348
Important: vim security update
ELSA-2026-66348-0
ELSA-2026-66348-0: vim security update (IMPORTANT)
RLSA-2026:66366
Important: vim security update
RLSA-2026:66336
Important: vim security update
ELSA-2026-66366-0
ELSA-2026-66366-0: vim security update (IMPORTANT)
ELSA-2026-66336-0
ELSA-2026-66336-0: vim security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59857 Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725. | CVSS3: 5.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-59857 Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725. | CVSS3: 5.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-59857 Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in src/spell.c translates a word through a spell file's SAL sound-folding rules into a caller-owned result buffer, but its result writes are guarded with reslen < MAXWLEN, allowing reslen to reach MAXWLEN before res[reslen] = NUL writes one byte past the end of the MAXWLEN-element stack buffer. A boundary-length word passed to soundfold(), or reached via sound-based spell suggestion while a SAL-based spell language is active under a non-multibyte 8-bit encoding, can corrupt the eval_soundfold() stack frame and crash the editor. This issue is fixed in version 9.2.0725. | CVSS3: 5.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-59857 Vim is an open source, command line text editor. Prior to 9.2.0725, th ... | CVSS3: 5.5 | 0% Низкий | 2 месяца назад | |
ROS-20260819-80-0038 Уязвимость vim | CVSS3: 5.5 | 0% Низкий | 30 дней назад | |
ROS-20260819-73-0038 Уязвимость vim | CVSS3: 5.5 | 0% Низкий | 30 дней назад | |
BDU:2026-14505 Уязвимость функции spell_soundfold_sal() файла src/spell.c текстового редактора Vim, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21374-1 Security update for vim | 2 месяца назад | |||
SUSE-SU-2026:3458-1 Security update for vim | около 2 месяцев назад | |||
SUSE-SU-2026:3271-1 Security update for vim | около 2 месяцев назад | |||
SUSE-SU-2026:3237-1 Security update for vim | около 2 месяцев назад | |||
RLSA-2026:66348 Important: vim security update | 7 дней назад | |||
ELSA-2026-66348-0 ELSA-2026-66348-0: vim security update (IMPORTANT) | 8 дней назад | |||
RLSA-2026:66366 Important: vim security update | 6 дней назад | |||
RLSA-2026:66336 Important: vim security update | 6 дней назад | |||
ELSA-2026-66366-0 ELSA-2026-66366-0: vim security update (IMPORTANT) | 8 дней назад | |||
ELSA-2026-66336-0 ELSA-2026-66336-0: vim security update (IMPORTANT) | 8 дней назад |
Уязвимостей на страницу