Vulnerabilidades em vim

231 resultados
Análise Vexday

O editor de texto Vim acumula 217 CVEs catalogadas, volume considerável para uma ferramenta de linha de comando, com 22 novas entradas registradas apenas nos últimos 90 dias — indicando atividade contínua de pesquisa e reporte de falhas. Apesar desse volume, nenhuma CVE atingiu severidade crítica, nenhuma possui prova de conceito pública disponível e a taxa de exploração ativa é zero, posicionando o Vim abaixo da média geral do catálogo CISA KEV. A falha de maior atenção no momento é CVE-2022-0572, com escore EPSS de 0,2658 — o mais alto observado no conjunto —, e o tipo de falha predominante é CWE-122 (heap-based buffer overflow), padrão que exige atenção em ambientes onde o editor processa arquivos de origens não confiáveis. O perfil geral sugere risco operacional moderado e gerenciável, desde que atualizações sejam aplicadas de forma consistente.

CVE-2025-22134MEDIUMheap-buffer-overflow with visual mode in Vim < 9.1.1003EPSS 0.4%CVE-2024-41957MEDIUMVim double free in src/alloc.c:616EPSS 0.4%CVE-2023-46246MEDIUMInteger Overflow in :history command in VimEPSS 0.4%CVE-2024-43374MEDIUMVim heap-use-after-free in src/arglist.c:207EPSS 0.4%CVE-2025-55158MEDIUMVim double-free vulnerability during Vim9 script import operationsEPSS 0.4%CVE-2025-55157MEDIUMVim heap use-after-free vulnerability when processing recursive tuple data typesEPSS 0.3%CVE-2026-73078HIGHVim: Arbitrary Code Execution via Netrw Menu ConstructionEPSS 0.3%CVE-2024-41965MEDIUMVim < v9.1.0648 has a double-free in dialog_changed()EPSS 0.3%CVE-2024-43790MEDIUMheap-buffer-overflow in do_search() in Vim < 9.1.0689EPSS 0.3%CVE-2026-52859MEDIUMVim: Out-of-bounds Read in Terminal Screen SnapshotEPSS 0.3%CVE-2024-45306MEDIUMheap-buffer-overflow in VimEPSS 0.3%CVE-2024-43802MEDIUMheap-buffer-overflow in ins_typebuf() in Vim < 9.1.0697EPSS 0.3%CVE-2026-26269MEDIUMVim has a Netbeans specialKeys Stack Buffer OverflowEPSS 0.3%CVE-2024-47814LOWuse-after-free when closing buffers in VimEPSS 0.3%CVE-2025-24014MEDIUMsegmentation fault in win_line() in Vim < 9.1.1043EPSS 0.3%CVE-2026-47162HIGHVim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory nameEPSS 0.3%CVE-2025-53905MEDIUMVim has path traversial issue with tar.vim and special crafted tar filesEPSS 0.3%CVE-2026-45130MEDIUMVim: Heap Buffer Overflow in spell file loadingEPSS 0.2%CVE-2025-26603MEDIUMheap-use-after-free in function str_to_reg in vim/vimEPSS 0.2%CVE-2026-52860HIGHVim: Arbitrary Code Execution via Python Omni-CompletionEPSS 0.2%