Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

fstec логотип

BDU:2026-06512

3 месяца назад

Уязвимость функции :find текстового редактора vim, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260626-73-0022

около 1 месяца назад

Уязвимость vim

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2026-44656

3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-44656

3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-44656

3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-44656

3 месяца назад

Vim: OS Command Injection via 'path' completion

EPSS: Низкий
debian логотип

CVE-2026-44656

3 месяца назад

Vim is an open source, command line text editor. Prior to version 9.2. ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2236-1

2 месяца назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2233-1

2 месяца назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20828-1

2 месяца назад

Security update for vim

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2313-1

около 2 месяцев назад

Security update for vim

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-06512

Уязвимость функции :find текстового редактора vim, позволяющая нарушителю выполнить произвольный код или вызвать отказ в обслуживании

CVSS3: 7.8
1%
Низкий
3 месяца назад
redos логотип
ROS-20260626-73-0022

Уязвимость vim

CVSS3: 7.8
1%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-44656

Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435.

CVSS3: 5.3
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-44656

Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435.

CVSS3: 5.3
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-44656

Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick-enclosed shell commands, those commands are executed during file name completion. Because the path option lacks the P_SECURE flag, it can be set from a modeline, allowing an attacker who controls the contents of a file to execute arbitrary shell commands when the user opens that file in Vim and triggers :find completion. This issue has been patched in version 9.2.0435.

CVSS3: 5.3
1%
Низкий
3 месяца назад
msrc логотип
CVE-2026-44656

Vim: OS Command Injection via 'path' completion

1%
Низкий
3 месяца назад
debian логотип
CVE-2026-44656

Vim is an open source, command line text editor. Prior to version 9.2. ...

CVSS3: 5.3
1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2236-1

Security update for vim

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2233-1

Security update for vim

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20828-1

Security update for vim

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2313-1

Security update for vim

около 2 месяцев назад

Уязвимостей на страницу