cbcvebase.
CVE-2025-1215
published 2025-02-12

CVE-2025-1215: A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.53%
41.3th percentile
A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianvim< vim 2:9.1.1113-1 (forky)vim 2:9.1.1113-1 (forky)
msrcazl3_vim_9.1.0791-4_on_azure_linux_3.0
msrccbl2_libinput_1.21.0-1_on_cbl_mariner_2.0
msrccbl2_vim_9.1.0791-4_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_libinput_1.16.5-1_on_cbl_mariner_1.0
vimvim< 9.1.10979.1.1097
vimvim
vimvim>= 0 < 2:9.1.1113-12:9.1.1113-1
vimvim>= 0 < 2:9.1.1113-12:9.1.1113-1
vimvim>= 0 < 2:8.1.2269-1ubuntu5.322:8.1.2269-1ubuntu5.32
vimvim>= 0 < 2:8.2.3995-1ubuntu2.242:8.2.3995-1ubuntu2.24
vimvim>= 0 < 2:9.1.0016-1ubuntu7.82:9.1.0016-1ubuntu7.8
vimvim>= 0 < 2:7.4.052-1ubuntu3.1+esm212:7.4.052-1ubuntu3.1+esm21
vimvim>= 0 < 2:7.4.1689-3ubuntu1.5+esm272:7.4.1689-3ubuntu1.5+esm27
vimvim>= 0 < 2:8.0.1453-1ubuntu1.13+esm122:8.0.1453-1ubuntu1.13+esm12

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.02.4LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv2.4LOW
vendor_msrc7.8HIGH
vendor_ubuntu2.8LOW
vendor_debian2.4LOW
vendor_redhat2.4LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.