Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

ubuntu логотип

CVE-2026-25749

6 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled 'helpfile' option value into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without any bounds checking. This issue has been patched in version 9.1.2132.

CVSS3: 6.6
EPSS: Низкий
redhat логотип

CVE-2026-25749

6 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled 'helpfile' option value into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without any bounds checking. This issue has been patched in version 9.1.2132.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-25749

6 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled 'helpfile' option value into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without any bounds checking. This issue has been patched in version 9.1.2132.

CVSS3: 6.6
EPSS: Низкий
debian логотип

CVE-2026-25749

6 месяцев назад

Vim is an open source, command line text editor. Prior to version 9.1. ...

CVSS3: 6.6
EPSS: Низкий
redos логотип

ROS-20260319-73-0035

4 месяца назад

Уязвимость vim

CVSS3: 6.6
EPSS: Низкий
rocky логотип

RLSA-2026:5602

4 месяца назад

Moderate: vim security update

EPSS: Низкий
rocky логотип

RLSA-2026:4715

4 месяца назад

Moderate: vim security update

EPSS: Низкий
rocky логотип

RLSA-2026:4442

5 месяцев назад

Moderate: vim security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-5602

4 месяца назад

ELSA-2026-5602: vim security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-4715

5 месяцев назад

ELSA-2026-4715: vim security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-4442

5 месяцев назад

ELSA-2026-4442: vim security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2026-05072

6 месяцев назад

Уязвимость функции get_tagfname() файла src/tag.c текстового редактора vim, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.6
EPSS: Низкий
oracle-oval логотип

ELSA-2026-6617

3 месяца назад

ELSA-2026-6617: vim security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-25749

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled 'helpfile' option value into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without any bounds checking. This issue has been patched in version 9.1.2132.

CVSS3: 6.6
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-25749

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled 'helpfile' option value into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without any bounds checking. This issue has been patched in version 9.1.2132.

CVSS3: 7.3
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-25749

Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled 'helpfile' option value into a fixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using an unsafe STRCPY() operation without any bounds checking. This issue has been patched in version 9.1.2132.

CVSS3: 6.6
0%
Низкий
6 месяцев назад
debian логотип
CVE-2026-25749

Vim is an open source, command line text editor. Prior to version 9.1. ...

CVSS3: 6.6
0%
Низкий
6 месяцев назад
redos логотип
ROS-20260319-73-0035

Уязвимость vim

CVSS3: 6.6
0%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:5602

Moderate: vim security update

0%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:4715

Moderate: vim security update

0%
Низкий
4 месяца назад
rocky логотип
RLSA-2026:4442

Moderate: vim security update

0%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2026-5602

ELSA-2026-5602: vim security update (MODERATE)

4 месяца назад
oracle-oval логотип
ELSA-2026-4715

ELSA-2026-4715: vim security update (MODERATE)

5 месяцев назад
oracle-oval логотип
ELSA-2026-4442

ELSA-2026-4442: vim security update (MODERATE)

5 месяцев назад
fstec логотип
BDU:2026-05072

Уязвимость функции get_tagfname() файла src/tag.c текстового редактора vim, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.6
0%
Низкий
6 месяцев назад
oracle-oval логотип
ELSA-2026-6617

ELSA-2026-6617: vim security update (IMPORTANT)

3 месяца назад

Уязвимостей на страницу