Debian Vim vulnerabilities
223 known vulnerabilities affecting debian/vim.
Total CVEs
223
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH40MEDIUM21LOW155
Vulnerabilities
Page 3 of 12
CVE-2022-1942P3HIGHCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-1942 [HIGH] CVE-2022-1942: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2022-2125P3LOWCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-2125 [HIGH] CVE-2022-2125: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2022-1897P3HIGHCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-1897 [HIGH] CVE-2022-1897: vim - Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2022-2129P3HIGHCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-2129 [HIGH] CVE-2022-2129: vim - Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2022-1733P3LOWCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-1733 [HIGH] CVE-2022-1733: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2021-3928P3LOWCVSS 7.8fixed in vim 2:8.2.3995-1 (bookworm)2021
CVE-2021-3928 [HIGH] CVE-2021-3928: vim - vim is vulnerable to Use of Uninitialized Variable
vim is vulnerable to Use of Uninitialized Variable
Scope: local
bookworm: resolved (fixed in 2:8.2.3995-1)
bullseye: open
forky: resolved (fixed in 2:8.2.3995-1)
sid: resolved (fixed in 2:8.2.3995-1)
trixie: resolved (fixed in 2:8.2.3995-1)
debian
CVE-2022-4141P3HIGHCVSS 7.8fixed in vim 2:9.0.1000-1 (bookworm)2022
CVE-2022-4141 [HIGH] CVE-2022-4141: vim - Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker...
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
Scope: local
bookworm: resolved (fixed in 2:9.0.1000-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.1000-1)
sid: resolved (fixed in 2:9.0.1000-1)
trixie: resolved (fixed in 2:9.0.1
debian
CVE-2022-0361P3HIGHCVSS 7.8fixed in vim 2:8.2.4659-1 (bookworm)2022
CVE-2022-0361 [HIGH] CVE-2022-0361: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:8.2.4659-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:8.2.4659-1)
sid: resolved (fixed in 2:8.2.4659-1)
trixie: resolved (fixed in 2:8.2.4659-1)
debian
CVE-2022-0417P3HIGHCVSS 7.8fixed in vim 2:8.2.4659-1 (bookworm)2022
CVE-2022-0417 [HIGH] CVE-2022-0417: vim - Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:8.2.4659-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:8.2.4659-1)
sid: resolved (fixed in 2:8.2.4659-1)
trixie: resolved (fixed in 2:8.2.4659-1)
debian
CVE-2022-0392P3HIGHCVSS 7.8fixed in vim 2:8.2.4659-1 (bookworm)2022
CVE-2022-0392 [HIGH] CVE-2022-0392: vim - Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:8.2.4659-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:8.2.4659-1)
sid: resolved (fixed in 2:8.2.4659-1)
trixie: resolved (fixed in 2:8.2.4659-1)
debian
CVE-2022-0408P3LOWCVSS 7.8fixed in vim 2:8.2.4659-1 (bookworm)2022
CVE-2022-0408 [HIGH] CVE-2022-0408: vim - Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:8.2.4659-1)
bullseye: open
forky: resolved (fixed in 2:8.2.4659-1)
sid: resolved (fixed in 2:8.2.4659-1)
trixie: resolved (fixed in 2:8.2.4659-1)
debian
CVE-2022-2304P3HIGHCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-2304 [HIGH] CVE-2022-2304: vim - Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2022-2288P3HIGHCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-2288 [HIGH] CVE-2022-2288: vim - Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: resolved
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2022-2210P3LOWCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-2210 [HIGH] CVE-2022-2210: vim - Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2022-0943P3LOWCVSS 7.8fixed in vim 2:8.2.4659-1 (bookworm)2022
CVE-2022-0943 [HIGH] CVE-2022-0943: vim - Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8...
Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
Scope: local
bookworm: resolved (fixed in 2:8.2.4659-1)
bullseye: open
forky: resolved (fixed in 2:8.2.4659-1)
sid: resolved (fixed in 2:8.2.4659-1)
trixie: resolved (fixed in 2:8.2.4659-1)
debian
CVE-2023-4735P3LOWCVSS 7.8fixed in vim 2:9.0.1894-1 (forky)2023
CVE-2023-4735 [HIGH] CVE-2023-4735: vim - Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1847.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2:9.0.1894-1)
sid: resolved (fixed in 2:9.0.1894-1)
trixie: resolved (fixed in 2:9.0.1894-1)
debian
CVE-2007-2438P3LOWCVSS 7.6fixed in vim 1:7.1-022+1 (bookworm)2007
CVE-2007-2438 [HIGH] CVE-2007-2438: vim - The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedke...
The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.
Scope: local
bookworm: resolved (fixed in 1:7.1-022+1)
bullseye: resolved (fixed in 1:7.1-022+1)
forky: resolved (fixed in 1:7.1-022+1)
sid: resolved (fixed in 1:7.1-022+1)
tr
debian
CVE-2019-20079P3HIGHCVSS 7.8fixed in vim 2:8.1.2136-1 (bookworm)2019
CVE-2019-20079 [HIGH] CVE-2019-20079: vim - The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
The autocmd feature in window.c in Vim before 8.1.2136 accesses freed memory.
Scope: local
bookworm: resolved (fixed in 2:8.1.2136-1)
bullseye: resolved (fixed in 2:8.1.2136-1)
forky: resolved (fixed in 2:8.1.2136-1)
sid: resolved (fixed in 2:8.1.2136-1)
trixie: resolved (fixed in 2:8.1.2136-1)
debian
CVE-2022-0685P3LOWCVSS 7.8fixed in vim 2:8.2.4659-1 (bookworm)2022
CVE-2022-0685 [HIGH] CVE-2022-0685: vim - Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.441...
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
Scope: local
bookworm: resolved (fixed in 2:8.2.4659-1)
bullseye: open
forky: resolved (fixed in 2:8.2.4659-1)
sid: resolved (fixed in 2:8.2.4659-1)
trixie: resolved (fixed in 2:8.2.4659-1)
debian
CVE-2022-1851P3LOWCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-1851 [HIGH] CVE-2022-1851: vim - Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian