Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

ubuntu логотип

CVE-2026-57451

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline after a line's text and returns it as the number of 32-byte textprop_T entries that follow. The only check is a floor that guarantees room for a single entry; the count is never checked against the amount of data actually present. A line that declares a large count while carrying little data causes consumers to read far past the end of the line buffer. Such a line can be delivered through a crafted undo file, leading to a crash. This vulnerability is fixed in 9.2.0670.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-57451

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline after a line's text and returns it as the number of 32-byte textprop_T entries that follow. The only check is a floor that guarantees room for a single entry; the count is never checked against the amount of data actually present. A line that declares a large count while carrying little data causes consumers to read far past the end of the line buffer. Such a line can be delivered through a crafted undo file, leading to a crash. This vulnerability is fixed in 9.2.0670.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2026-57451

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline after a line's text and returns it as the number of 32-byte textprop_T entries that follow. The only check is a floor that guarantees room for a single entry; the count is never checked against the amount of data actually present. A line that declares a large count while carrying little data causes consumers to read far past the end of the line buffer. Such a line can be delivered through a crafted undo file, leading to a crash. This vulnerability is fixed in 9.2.0670.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-57451

3 месяца назад

Vim: Out-of-bounds Read in Text Property Count

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-57451

3 месяца назад

Vim is an open source, command line text editor. Prior to 9.2.0670, ge ...

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260819-80-0030

30 дней назад

Уязвимость vim

CVSS3: 6.1
EPSS: Низкий
redos логотип

ROS-20260819-73-0030

30 дней назад

Уязвимость vim

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-57451

Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline after a line's text and returns it as the number of 32-byte textprop_T entries that follow. The only check is a floor that guarantees room for a single entry; the count is never checked against the amount of data actually present. A line that declares a large count while carrying little data causes consumers to read far past the end of the line buffer. Such a line can be delivered through a crafted undo file, leading to a crash. This vulnerability is fixed in 9.2.0670.

CVSS3: 5.3
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-57451

Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline after a line's text and returns it as the number of 32-byte textprop_T entries that follow. The only check is a floor that guarantees room for a single entry; the count is never checked against the amount of data actually present. A line that declares a large count while carrying little data causes consumers to read far past the end of the line buffer. Such a line can be delivered through a crafted undo file, leading to a crash. This vulnerability is fixed in 9.2.0670.

CVSS3: 5.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57451

Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline after a line's text and returns it as the number of 32-byte textprop_T entries that follow. The only check is a floor that guarantees room for a single entry; the count is never checked against the amount of data actually present. A line that declares a large count while carrying little data causes consumers to read far past the end of the line buffer. Such a line can be delivered through a crafted undo file, leading to a crash. This vulnerability is fixed in 9.2.0670.

CVSS3: 5.3
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-57451

Vim: Out-of-bounds Read in Text Property Count

CVSS3: 5.3
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-57451

Vim is an open source, command line text editor. Prior to 9.2.0670, ge ...

CVSS3: 5.3
0%
Низкий
3 месяца назад
redos логотип
ROS-20260819-80-0030

Уязвимость vim

CVSS3: 6.1
0%
Низкий
30 дней назад
redos логотип
ROS-20260819-73-0030

Уязвимость vim

CVSS3: 6.1
0%
Низкий
30 дней назад

Уязвимостей на страницу