Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

fstec логотип

BDU:2026-14509

3 месяца назад

Уязвимость функции tree_count_words() файла src/spellfile.c текстового редактора Vim, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2026-55693

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2026-55693

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-55693

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2026-55693

3 месяца назад

Vim: Out-of-bounds Write in Spell File Word Count

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2026-55693

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0653, th ...

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260819-80-0034

30 дней назад

Уязвимость vim

CVSS3: 7.8
EPSS: Низкий
redos логотип

ROS-20260819-73-0034

30 дней назад

Уязвимость vim

CVSS3: 7.8
EPSS: Низкий
rocky логотип

RLSA-2026:48703

около 2 месяцев назад

Important: vim security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-48703

около 2 месяцев назад

ELSA-2026-48703: vim security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:48650

около 2 месяцев назад

Important: vim security update

EPSS: Низкий
rocky логотип

RLSA-2026:47982

около 2 месяцев назад

Important: vim security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-48650

около 2 месяцев назад

ELSA-2026-48650: vim security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-47982

около 2 месяцев назад

ELSA-2026-47982: vim security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-14509

Уязвимость функции tree_count_words() файла src/spellfile.c текстового редактора Vim, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 7.8
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-55693

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.

CVSS3: 7.8
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-55693

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.

CVSS3: 7.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-55693

Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c fills in the word-count fields of a spell-file word trie by walking it iteratively with a depth counter. The counter is bounded only by the trie structure itself; it is never checked against the size of the fixed MAXWLEN-element stack arrays it indexes (arridx[], curi[], wordcount[]). A crafted .spl/.sug file pair, loaded when the user invokes spell suggestion, can drive the descent arbitrarily deep, so the function writes past the end of those arrays. This is a stack out-of-bounds write that corrupts the call frame and crashes the editor. This vulnerability is fixed in 9.2.0653.

CVSS3: 7.8
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-55693

Vim: Out-of-bounds Write in Spell File Word Count

CVSS3: 7.8
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-55693

Vim is an open source, command line text editor. Prior to 9.2.0653, th ...

CVSS3: 7.8
0%
Низкий
3 месяца назад
redos логотип
ROS-20260819-80-0034

Уязвимость vim

CVSS3: 7.8
0%
Низкий
30 дней назад
redos логотип
ROS-20260819-73-0034

Уязвимость vim

CVSS3: 7.8
0%
Низкий
30 дней назад
rocky логотип
RLSA-2026:48703

Important: vim security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-48703

ELSA-2026-48703: vim security update (IMPORTANT)

около 2 месяцев назад
rocky логотип
RLSA-2026:48650

Important: vim security update

около 2 месяцев назад
rocky логотип
RLSA-2026:47982

Important: vim security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-48650

ELSA-2026-48650: vim security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-47982

ELSA-2026-47982: vim security update (IMPORTANT)

около 2 месяцев назад

Уязвимостей на страницу