Количество 41
Количество 41
ROS-20260819-73-0032
Уязвимость vim
BDU:2026-14499
Уязвимость функций spell_soundfold_sofo() файла src/spell.c текстового редактора Vim, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
CVE-2026-57456
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.
CVE-2026-57456
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.
CVE-2026-57456
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.
CVE-2026-57456
Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings
CVE-2026-57456
Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ...
CVE-2026-59858
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.
CVE-2026-59858
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.
CVE-2026-59858
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.
CVE-2026-59858
Vim is an open source, command line text editor. Prior to 9.2.0735, th ...
ROS-20260819-80-0033
Уязвимость vim
ROS-20260819-73-0033
Уязвимость vim
BDU:2026-14514
Уязвимость механизма автодополнения PHP-кода Python omni-completion модуля python3complete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код
ROS-20260819-80-0036
Уязвимость vim
ROS-20260819-73-0036
Уязвимость vim
BDU:2026-14504
Уязвимость механизма автодополнения C omni-completion модуля runtime/autoload/ccomplete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код
openSUSE-SU-2026:21374-1
Security update for vim
SUSE-SU-2026:3458-1
Security update for vim
SUSE-SU-2026:3271-1
Security update for vim
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
ROS-20260819-73-0032 Уязвимость vim | CVSS3: 7 | 0% Низкий | 30 дней назад | |
BDU:2026-14499 Уязвимость функций spell_soundfold_sofo() файла src/spell.c текстового редактора Vim, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57456 Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57456 Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57456 Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57456 Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-57456 Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ... | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
CVE-2026-59858 Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-59858 Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
CVE-2026-59858 Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
CVE-2026-59858 Vim is an open source, command line text editor. Prior to 9.2.0735, th ... | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
ROS-20260819-80-0033 Уязвимость vim | CVSS3: 7.8 | 0% Низкий | 30 дней назад | |
ROS-20260819-73-0033 Уязвимость vim | CVSS3: 7.8 | 0% Низкий | 30 дней назад | |
BDU:2026-14514 Уязвимость механизма автодополнения PHP-кода Python omni-completion модуля python3complete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
ROS-20260819-80-0036 Уязвимость vim | CVSS3: 7.8 | 0% Низкий | 30 дней назад | |
ROS-20260819-73-0036 Уязвимость vim | CVSS3: 7.8 | 0% Низкий | 30 дней назад | |
BDU:2026-14504 Уязвимость механизма автодополнения C omni-completion модуля runtime/autoload/ccomplete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
openSUSE-SU-2026:21374-1 Security update for vim | 2 месяца назад | |||
SUSE-SU-2026:3458-1 Security update for vim | около 2 месяцев назад | |||
SUSE-SU-2026:3271-1 Security update for vim | около 2 месяцев назад |
Уязвимостей на страницу