Search CVE reports


Toggle filters

1 – 10 of 238 results


CVE-2026-39881

Medium priority
Needs evaluation

[Ex command injection in Vims NetBeans integration]

1 affected package

vim

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vim Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-35177

Medium priority
Needs evaluation

Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix...

1 affected package

vim

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vim Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-34982

Medium priority
Vulnerable

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader`...

1 affected package

vim

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vim Vulnerable Vulnerable Vulnerable Not affected
Show less packages

CVE-2026-34714

Medium priority
Not affected

Vim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.

1 affected package

vim

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vim Not affected Not affected Not affected Not affected
Show less packages

CVE-2026-33412

Medium priority
Vulnerable

Vim is an open source, command line text editor. Prior to version 9.2.0202, a command injection vulnerability exists in Vim's glob() function on Unix-like systems. By including a newline character (\n) in a pattern passed to...

1 affected package

vim

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vim Vulnerable Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2026-32249

Medium priority
Vulnerable

Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a character range (e.g. [0-0\u05bb]),...

1 affected package

vim

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vim Vulnerable Not affected Not affected Not affected
Show less packages

CVE-2026-28422

Medium priority
Fixed

Vim is an open source, command line text editor. Prior to version 9.2.0078, a stack-buffer-overflow occurs in `build_stl_str_hl()` when rendering a statusline with a multi-byte fill character on a very wide terminal. Version...

1 affected package

vim

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vim Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-28421

Medium priority
Fixed

Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read...

1 affected package

vim

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vim Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-28420

Medium priority
Fixed

Vim is an open source, command line text editor. Prior to version 9.2.0076, a heap-based buffer overflow WRITE and an out-of-bounds READ exist in Vim's terminal emulator when processing maximum combining characters from...

1 affected package

vim

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vim Fixed Fixed Fixed Fixed
Show less packages

CVE-2026-28419

Medium priority
Fixed

Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the...

1 affected package

vim

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
vim Fixed Fixed Fixed Fixed
Show less packages