Vim
36 known vulnerabilities
Top Products
Vim is an open source, command line text editor. Prior to 9.2.0735, the C omni-completion script in runtime/autoload/cco
Vim is an open source, command line text editor. Prior to 9.2.0725, the single-byte branch of spell_soundfold_sal() in s
Vim is an open source, command line text editor. Prior to 9.2.0736, the PHP omni-completion script in runtime/autoload/p
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/pytho
Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in
Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a v
Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.
Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04
Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 pr
Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s
Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a
Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c f
Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes recons
Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/termin
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3
Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:s
Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exi
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimu
Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compou
Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists
Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists
Vim is an open source, command line text editor. Prior to 9.2.0357, A command injection vulnerability exists in Vim's ta
Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allo
Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbi
Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configurat
Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in
Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encoun
Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl
Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentati
Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an ou
Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim'
Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds r
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists
Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim'
Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists
Frequently Asked Questions
How many CVEs affect Vim?
Vim has 36 CVE records in our database, including 1 critical and 11 high severity vulnerabilities.
What are the most severe Vim vulnerabilities?
Vim has 1 critical severity (CVSS 9.0+) and 11 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Vim vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Vim products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Vim Vulnerabilities
CyberStrike scans your infrastructure for Vim vulnerabilities and provides real-time remediation guidance.
Get Started