Debian Vim vulnerabilities
223 known vulnerabilities affecting debian/vim.
Total CVEs
223
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH40MEDIUM21LOW155
Vulnerabilities
Page 7 of 12
CVE-2022-3235P4LOWCVSS 7.8fixed in vim 2:9.0.0626-1 (bookworm)2022
CVE-2022-3235 [HIGH] CVE-2022-3235: vim - Use After Free in GitHub repository vim/vim prior to 9.0.0490.
Use After Free in GitHub repository vim/vim prior to 9.0.0490.
Scope: local
bookworm: resolved (fixed in 2:9.0.0626-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0626-1)
sid: resolved (fixed in 2:9.0.0626-1)
trixie: resolved (fixed in 2:9.0.0626-1)
debian
CVE-2023-0288P4LOWCVSS 7.8fixed in vim 2:9.0.1378-1 (bookworm)2023
CVE-2023-0288 [HIGH] CVE-2023-0288: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189.
Scope: local
bookworm: resolved (fixed in 2:9.0.1378-1)
bullseye: open
forky: resolved (fixed in 2:9.0.1378-1)
sid: resolved (fixed in 2:9.0.1378-1)
trixie: resolved (fixed in 2:9.0.1378-1)
debian
CVE-2022-3099P4HIGHCVSS 7.8fixed in vim 2:9.0.0626-1 (bookworm)2022
CVE-2022-3099 [HIGH] CVE-2022-3099: vim - Use After Free in GitHub repository vim/vim prior to 9.0.0360.
Use After Free in GitHub repository vim/vim prior to 9.0.0360.
Scope: local
bookworm: resolved (fixed in 2:9.0.0626-1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.0626-1)
sid: resolved (fixed in 2:9.0.0626-1)
trixie: resolved (fixed in 2:9.0.0626-1)
debian
CVE-2022-3256P4LOWCVSS 7.8fixed in vim 2:9.0.0626-1 (bookworm)2022
CVE-2022-3256 [HIGH] CVE-2022-3256: vim - Use After Free in GitHub repository vim/vim prior to 9.0.0530.
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
Scope: local
bookworm: resolved (fixed in 2:9.0.0626-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0626-1)
sid: resolved (fixed in 2:9.0.0626-1)
trixie: resolved (fixed in 2:9.0.0626-1)
debian
CVE-2022-2849P4LOWCVSS 7.8fixed in vim 2:9.0.0229-1 (bookworm)2022
CVE-2022-2849 [HIGH] CVE-2022-2849: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.
Scope: local
bookworm: resolved (fixed in 2:9.0.0229-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0229-1)
sid: resolved (fixed in 2:9.0.0229-1)
trixie: resolved (fixed in 2:9.0.0229-1)
debian
CVE-2026-35177P4MEDIUMCVSS 4.1fixed in vim 2:9.2.0315-1 (sid)2026
CVE-2026-35177 [MEDIUM] CVE-2026-35177: vim - Vim is an open source, command line text editor. Prior to 9.2.0280, a path trave...
Vim is an open source, command line text editor. Prior to 9.2.0280, a path traversal bypass in Vim's zip.vim plugin allows overwriting of arbitrary files when opening specially crafted zip archives, circumventing the previous fix for CVE-2025-53906. This vulnerability is fixed in 9.2.0280.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in
debian
CVE-2007-2953P4LOWCVSS 6.8fixed in vim 1:7.1-056+1 (bookworm)2007
CVE-2007-2953 [MEDIUM] CVE-2007-2953: vim - Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim...
Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.
Scope: local
bookworm: resolved (fixed in 1:7.1-056+1)
bullseye: resolved (fixed in 1:7.1-056+
debian
CVE-2022-1620P4LOWCVSS 7.5fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-1620 [HIGH] CVE-2022-1620: vim - NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitH...
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vim prior to 8.2.4901. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 allows attackers to cause a denial of service (application crash) via a crafted input.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: open
forky: resolved (fixed
debian
CVE-2022-2816P4LOWCVSS 7.8fixed in vim 2:9.0.0229-1 (bookworm)2022
CVE-2022-2816 [HIGH] CVE-2022-2816: vim - Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.
Scope: local
bookworm: resolved (fixed in 2:9.0.0229-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0229-1)
sid: resolved (fixed in 2:9.0.0229-1)
trixie: resolved (fixed in 2:9.0.0229-1)
debian
CVE-2022-2845P4LOWCVSS 7.8fixed in vim 2:9.0.0229-1 (bookworm)2022
CVE-2022-2845 [HIGH] CVE-2022-2845: vim - Improper Validation of Specified Quantity in Input in GitHub repository vim/vim ...
Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.
Scope: local
bookworm: resolved (fixed in 2:9.0.0229-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0229-1)
sid: resolved (fixed in 2:9.0.0229-1)
trixie: resolved (fixed in 2:9.0.0229-1)
debian
CVE-2023-2610P4HIGHCVSS 7.8fixed in vim 2:9.0.1378-2+deb12u1 (bookworm)2023
CVE-2023-2610 [HIGH] CVE-2023-2610: vim - Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.1532.
Scope: local
bookworm: resolved (fixed in 2:9.0.1378-2+deb12u1)
bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2)
forky: resolved (fixed in 2:9.0.1658-1)
sid: resolved (fixed in 2:9.0.1658-1)
trixie: resolved (fixed in 2:9.0.1658-1)
debian
CVE-2022-2581P4LOWCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-2581 [HIGH] CVE-2022-2581: vim - Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104.
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0104.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2022-2571P4LOWCVSS 7.8fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-2571 [HIGH] CVE-2022-2571: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0101.
Scope: local
bookworm: resolved (fixed in 2:9.0.0135-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0135-1)
sid: resolved (fixed in 2:9.0.0135-1)
trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2023-0049P4LOWCVSS 7.8fixed in vim 2:9.0.1378-1 (bookworm)2023
CVE-2023-0049 [HIGH] CVE-2023-0049: vim - Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
Scope: local
bookworm: resolved (fixed in 2:9.0.1378-1)
bullseye: open
forky: resolved (fixed in 2:9.0.1378-1)
sid: resolved (fixed in 2:9.0.1378-1)
trixie: resolved (fixed in 2:9.0.1378-1)
debian
CVE-2023-3896P4LOWCVSS 7.8fixed in vim 2:9.0.1894-1 (forky)2023
CVE-2023-3896 [HIGH] CVE-2023-3896: vim - Divide By Zero in vim/vim from 9.0.1367-1 to 9.0.1367-3
Divide By Zero in vim/vim from 9.0.1367-1 to 9.0.1367-3
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2:9.0.1894-1)
sid: resolved (fixed in 2:9.0.1894-1)
trixie: resolved (fixed in 2:9.0.1894-1)
debian
CVE-2022-3591P4LOWCVSS 7.8fixed in vim 2:9.0.0813-1 (bookworm)2022
CVE-2022-3591 [HIGH] CVE-2022-3591: vim - Use After Free in GitHub repository vim/vim prior to 9.0.0789.
Use After Free in GitHub repository vim/vim prior to 9.0.0789.
Scope: local
bookworm: resolved (fixed in 2:9.0.0813-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0813-1)
sid: resolved (fixed in 2:9.0.0813-1)
trixie: resolved (fixed in 2:9.0.0813-1)
debian
CVE-2022-0714P4LOWCVSS 5.5fixed in vim 2:8.2.4659-1 (bookworm)2022
CVE-2022-0714 [MEDIUM] CVE-2022-0714: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
Scope: local
bookworm: resolved (fixed in 2:8.2.4659-1)
bullseye: open
forky: resolved (fixed in 2:8.2.4659-1)
sid: resolved (fixed in 2:8.2.4659-1)
trixie: resolved (fixed in 2:8.2.4659-1)
debian
CVE-2022-47024P4LOWCVSS 7.8fixed in vim 2:9.0.0626-1 (bookworm)2022
CVE-2022-47024 [HIGH] CVE-2022-47024: vim - A null pointer dereference issue was discovered in function gui_x11_create_blank...
A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts.
Scope: local
bookworm: resolved (fixed in 2:9.0.0626-1)
bullseye: open
forky: resolved (fixed in 2:9.0.0626-1)
sid: resolved (fixed in 2:9.0.0626-1)
trixie: resolved (f
debian
CVE-2023-0512P4LOWCVSS 7.8fixed in vim 2:9.0.1378-1 (bookworm)2023
CVE-2023-0512 [HIGH] CVE-2023-0512: vim - Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
Scope: local
bookworm: resolved (fixed in 2:9.0.1378-1)
bullseye: open
forky: resolved (fixed in 2:9.0.1378-1)
sid: resolved (fixed in 2:9.0.1378-1)
trixie: resolved (fixed in 2:9.0.1378-1)
debian
CVE-2023-1127P4LOWCVSS 7.8fixed in vim 2:9.0.1378-1 (bookworm)2023
CVE-2023-1127 [HIGH] CVE-2023-1127: vim - Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.
Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.
Scope: local
bookworm: resolved (fixed in 2:9.0.1378-1)
bullseye: resolved
forky: resolved (fixed in 2:9.0.1378-1)
sid: resolved (fixed in 2:9.0.1378-1)
trixie: resolved (fixed in 2:9.0.1378-1)
debian