Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 41

Количество 41

redos логотип

ROS-20260819-73-0032

30 дней назад

Уязвимость vim

CVSS3: 7
EPSS: Низкий
fstec логотип

BDU:2026-14499

3 месяца назад

Уязвимость функций spell_soundfold_sofo() файла src/spell.c текстового редактора Vim, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2026-57456

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-57456

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-57456

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2026-57456

3 месяца назад

Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-57456

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2026-59858

2 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-59858

2 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-59858

2 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-59858

2 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0735, th ...

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260819-80-0033

30 дней назад

Уязвимость vim

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260819-73-0033

30 дней назад

Уязвимость vim

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2026-14514

3 месяца назад

Уязвимость механизма автодополнения PHP-кода Python omni-completion модуля python3complete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260819-80-0036

30 дней назад

Уязвимость vim

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260819-73-0036

30 дней назад

Уязвимость vim

CVSS3: 7.8
EPSS: Низкий
fstec логотип

BDU:2026-14504

3 месяца назад

Уязвимость механизма автодополнения C omni-completion модуля runtime/autoload/ccomplete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21374-1

2 месяца назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3458-1

около 2 месяцев назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3271-1

около 2 месяцев назад

Security update for vim

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redos логотип
ROS-20260819-73-0032

Уязвимость vim

CVSS3: 7
0%
Низкий
30 дней назад
fstec логотип
BDU:2026-14499

Уязвимость функций spell_soundfold_sofo() файла src/spell.c текстового редактора Vim, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-57456

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS3: 7.8
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-57456

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS3: 7.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57456

Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dictionary. When reconstructing that source, each scope's docstring is inserted verbatim between triple quotes with no escaping, so a hostile buffer can break out of the triple-quoted literal and execute attacker-controlled Python during omni-completion. This vulnerability is fixed in 9.2.0699.

CVSS3: 7.8
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-57456

Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings

CVSS3: 7.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-57456

Vim is an open source, command line text editor. Prior to 9.2.0699, Vi ...

CVSS3: 7.8
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-59858

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.

CVSS3: 7.8
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-59858

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-59858

Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/ccomplete.vim interpolates the typeref: or typename: extension field of a tags entry, without escaping, into a :vimgrep pattern that is run through :execute. Because :vimgrep honors the bar as a command separator, a crafted tag field can close the search pattern and append an arbitrary Ex command; opening a hostile .c file whose project tags file contains such an entry and invoking C omni-completion runs that command as the editing user. This issue is fixed in version 9.2.0735.

CVSS3: 7.8
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-59858

Vim is an open source, command line text editor. Prior to 9.2.0735, th ...

CVSS3: 7.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20260819-80-0033

Уязвимость vim

CVSS3: 7.8
0%
Низкий
30 дней назад
redos логотип
ROS-20260819-73-0033

Уязвимость vim

CVSS3: 7.8
0%
Низкий
30 дней назад
fstec логотип
BDU:2026-14514

Уязвимость механизма автодополнения PHP-кода Python omni-completion модуля python3complete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
0%
Низкий
3 месяца назад
redos логотип
ROS-20260819-80-0036

Уязвимость vim

CVSS3: 7.8
0%
Низкий
30 дней назад
redos логотип
ROS-20260819-73-0036

Уязвимость vim

CVSS3: 7.8
0%
Низкий
30 дней назад
fstec логотип
BDU:2026-14504

Уязвимость механизма автодополнения C omni-completion модуля runtime/autoload/ccomplete.vim текстового редактора Vim, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.8
0%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21374-1

Security update for vim

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3458-1

Security update for vim

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3271-1

Security update for vim

около 2 месяцев назад

Уязвимостей на страницу