Debian Vim vulnerabilities
223 known vulnerabilities affecting debian/vim.
Total CVEs
223
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH40MEDIUM21LOW155
Vulnerabilities
Page 2 of 12
CVE-2008-3074P3CRITICALCVSS 9.3fixed in vim 2:7.2.010-1 (bookworm)2008
CVE-2008-3074 [CRITICAL] CVE-2008-3074: vim - The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-...
The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a tar archive and possibly (2) the filename of the first file in a tar archive, which is not properly handled by the VIM TAR plugin (tar.vim) v.10 through v.22, as demons
debian
CVE-2026-26269P3MEDIUMCVSS 5.4fixed in vim 2:9.2.0119-1 (forky)2026
CVE-2026-26269 [MEDIUM] CVE-2026-26269: vim - Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buff...
Vim is an open source, command line text editor. Prior to 9.1.2148, a stack buffer overflow vulnerability exists in Vim's NetBeans integration when processing the specialKeys command, affecting Vim builds that enable and use the NetBeans feature. The Stack buffer overflow exists in special_keys() (in src/netbeans.c). The while (*tok) loop writes two bytes per iteratio
debian
CVE-2022-1616P3HIGHCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-1616 [HIGH] CVE-2022-1616: vim - Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895....
Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed
debian
CVE-2022-1621P3LOWCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-1621 [HIGH] CVE-2022-1621: vim - Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior...
Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixi
debian
CVE-2022-1619P3LOWCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-1619 [HIGH] CVE-2022-1619: vim - Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository ...
Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (
debian
CVE-2022-3705P3LOWCVSS 5.0fixed in vim 2:9.0.0813-1 (bookworm)2022
CVE-2022-3705 [MEDIUM] CVE-2022-3705: vim - A vulnerability was found in vim and classified as problematic. Affected by this...
A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version 9.0.0805 is able to address this issue. The name of the patch is d0fab10ed2a86698937e3c3fed2f10
debian
CVE-2002-1377P4MEDIUMCVSS 4.6PoCfixed in vim 6.1.263-1 (bookworm)2002
CVE-2002-1377 [MEDIUM] CVE-2002-1377: vim - vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitr...
vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed when vim is used to edit a malicious file, as demonstrated using mutt.
Scope: local
bookworm: resolved (fixed in 6.1.263-1)
bullseye: resolved (fixed in 6.1.263-1)
forky: resolved (fixed in 6.1.2
debian
CVE-2022-1720P3LOWCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-1720 [HIGH] CVE-2022-1720: vim - Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior t...
Buffer Over-read in function grab_file_name in GitHub repository vim/vim prior to 8.2.4956. This vulnerability is capable of crashing the software, memory modification, and possible remote execution.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed i
debian
CVE-2024-22667P3HIGHCVSS 7.8fixed in vim 2:9.0.1378-2+deb12u1 (bookworm)2024
CVE-2024-22667 [HIGH] CVE-2024-22667: vim - Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in...
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
Scope: local
bookworm: resolved (fixed in 2:9.0.1378-2+deb12u1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.2189-1)
sid: resolved (fixed in 2:9.0.218
debian
CVE-2026-28421P3MEDIUMCVSS 5.3fixed in vim 2:9.2.0119-1 (forky)2026
CVE-2026-28421 [MEDIUM] CVE-2026-28421: vim - Vim is an open source, command line text editor. Versions prior to 9.2.0077 have...
Vim is an open source, command line text editor. Versions prior to 9.2.0077 have a heap-buffer-overflow and a segmentation fault (SEGV) exist in Vim's swap file recovery logic. Both are caused by unvalidated fields read from crafted pointer blocks within a swap file. Version 9.2.0077 fixes the issue.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in
debian
CVE-2022-1629P3LOWCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-1629 [HIGH] CVE-2022-1629: vim - Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior ...
Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0
debian
CVE-2022-2000P3HIGHCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-2000 [HIGH] CVE-2022-2000: vim - Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2022-0351P3HIGHCVSS 7.8fixed in vim 2:8.2.4659-1 (bookworm)2022
CVE-2022-0351 [HIGH] CVE-2022-0351: vim - Access of Memory Location Before Start of Buffer in GitHub repository vim/vim pr...
Access of Memory Location Before Start of Buffer in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:8.2.4659-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:8.2.4659-1)
sid: resolved (fixed in 2:8.2.4659-1)
trixie: resolved (fixed in 2:8.2.4659-1)
debian
CVE-2022-1785P3HIGHCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-1785 [HIGH] CVE-2022-1785: vim - Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.4977.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2005-2368P3MEDIUMCVSS 9.3fixed in vim 1:6.3-085+1 (bookworm)2005
CVE-2005-2368 [CRITICAL] CVE-2005-2368: vim - vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted at...
vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.
Scope: local
bookworm: resolved (fixed in 1:6.3-085+1)
bullseye: resolved (fixed in 1:6.3-085+1)
forky: resolved (fixed in 1:6.3-085+1
debian
CVE-2023-5344P3HIGHCVSS 7.5fixed in vim 2:9.0.1378-2+deb12u1 (bookworm)2023
CVE-2023-5344 [HIGH] CVE-2023-5344: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
Scope: local
bookworm: resolved (fixed in 2:9.0.1378-2+deb12u1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.2018-1)
sid: resolved (fixed in 2:9.0.2018-1)
trixie: resolved (fixed in 2:9.0.2018-1)
debian
CVE-2022-3520P3LOWCVSS 9.8fixed in vim 2:9.0.0813-1 (bookworm)2022
CVE-2022-3520 [CRITICAL] CVE-2022-3520: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765.
Scope: local
bookworm: resolved (fixed in 2:9.0.0813-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0813-1)
sid: resolved (fixed in 2:9.0.0813-1)
trixie: resolved (fixed in 2:9.0.0813-1)
debian
CVE-2025-1215P3LOWCVSS 2.4fixed in vim 2:9.1.1113-1 (forky)2025
CVE-2025-1215 [LOW] CVE-2025-1215: vim - A vulnerability classified as problematic was found in vim up to 9.1.1096. This ...
A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc
debian
CVE-2022-0629P3LOWCVSS 7.8fixed in vim 2:8.2.4659-1 (bookworm)2022
CVE-2022-0629 [HIGH] CVE-2022-0629: vim - Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:8.2.4659-1)
bullseye: open
forky: resolved (fixed in 2:8.2.4659-1)
sid: resolved (fixed in 2:8.2.4659-1)
trixie: resolved (fixed in 2:8.2.4659-1)
debian
CVE-2022-0261P3HIGHCVSS 7.8fixed in vim 2:8.2.4659-1 (bookworm)2022
CVE-2022-0261 [HIGH] CVE-2022-0261: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:8.2.4659-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:8.2.4659-1)
sid: resolved (fixed in 2:8.2.4659-1)
trixie: resolved (fixed in 2:8.2.4659-1)
debian