cbcvebase.

Debian Vim vulnerabilities

223 known vulnerabilities affecting debian/vim.

Total CVEs
223
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH40MEDIUM21LOW155

Vulnerabilities

Page 8 of 12
CVE-2026-25749P4MEDIUMCVSS 6.6fixed in vim 2:9.1.2141-1 (forky)2026
CVE-2026-25749 [MEDIUM] CVE-2026-25749: vim - Vim is an open source, command line text editor. Prior to version 9.1.2132, a he... Vim is an open source, command line text editor. Prior to version 9.1.2132, a heap buffer overflow vulnerability exists in Vim's tag file resolution logic when processing the 'helpfile' option. The vulnerability is located in the get_tagfname() function in src/tag.c. When processing help file tags, Vim copies the user-controlled 'helpfile' option value into a fixed-si
debian
CVE-2019-20807P4MEDIUMCVSS 5.3fixed in vim 2:8.1.2136-1 (bookworm)2019
CVE-2019-20807 [MEDIUM] CVE-2019-20807: vim - In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execut... In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua). Scope: local bookworm: resolved (fixed in 2:8.1.2136-1) bullseye: resolved (fixed in 2:8.1.2136-1) forky: resolved (fixed in 2:8.1.2136-1) sid: resolved (fixed in 2:8.1.2136-1) trixie: resolved (fixed in 2:8.1.2
debian
CVE-2017-11109P4LOWCVSS 7.8fixed in vim 2:8.0.0197-5 (bookworm)2017
CVE-2017-11109 [HIGH] CVE-2017-11109: vim - Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly... Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NOTE: there might be a limited number of scenarios in which this has security relevance. Scope: local bookworm: resolved (fixed in 2:8.0.0197-5) bullseye: resolved (fixed in 2:8.0.0197-5) forky: resolved (fixed in 2:8.0.0197-
debian
CVE-2026-28419P4MEDIUMCVSS 5.3fixed in vim 2:9.2.0119-1 (forky)2026
CVE-2026-28419 [MEDIUM] CVE-2026-28419: vim - Vim is an open source, command line text editor. Prior to version 9.2.0075, a he... Vim is an open source, command line text editor. Prior to version 9.2.0075, a heap-based buffer underflow exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file where a delimiter appears at the start of a line, Vim attempts to read memory immediately preceding the allocated buffer. Version 9.2.0075 fixes the issue. Scope: local book
debian
CVE-2009-0316P4LOWCVSS 6.9fixed in vim 2:7.2.025-2 (bookworm)2009
CVE-2009-0316 [MEDIUM] CVE-2009-0316: vim - Untrusted search path vulnerability in src/if_python.c in the Python interface i... Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair. Scope
debian
CVE-2025-9390P4LOWCVSS 4.8fixed in vim 2:9.1.1829-1 (forky)2025
CVE-2025-9390 [MEDIUM] CVE-2025-9390: vim - A security flaw has been discovered in vim up to 9.1.1615. Affected by this vuln... A security flaw has been discovered in vim up to 9.1.1615. Affected by this vulnerability is the function main of the file src/xxd/xxd.c of the component xxd. The manipulation results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be exploited. Upgrading to version 9.1.1616 addresses this issue. The patch is
debian
CVE-2022-0393P4LOWCVSS 7.1fixed in vim 2:8.2.4659-1 (bookworm)2022
CVE-2022-0393 [HIGH] CVE-2022-0393: vim - Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. Scope: local bookworm: resolved (fixed in 2:8.2.4659-1) bullseye: open forky: resolved (fixed in 2:8.2.4659-1) sid: resolved (fixed in 2:8.2.4659-1) trixie: resolved (fixed in 2:8.2.4659-1)
debian
CVE-2022-2287P4LOWCVSS 7.1fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-2287 [HIGH] CVE-2022-2287: vim - Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. Out-of-bounds Read in GitHub repository vim/vim prior to 9.0. Scope: local bookworm: resolved (fixed in 2:9.0.0135-1) bullseye: open forky: resolved (fixed in 2:9.0.0135-1) sid: resolved (fixed in 2:9.0.0135-1) trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2024-41957P4LOWCVSS 4.5fixed in vim 2:9.1.0698-1 (forky)2024
CVE-2024-41957 [MEDIUM] CVE-2024-41957: vim - Vim is an open source command line text editor. Vim < v9.1.0647 has double free ... Vim is an open source command line text editor. Vim < v9.1.0647 has double free in src/alloc.c:616. When closing a window, the corresponding tagstack data will be cleared and freed. However a bit later, the quickfix list belonging to that window will also be cleared and if that quickfix list points to the same tagstack data, Vim will try to free it again, resulting in
debian
CVE-2023-1170P4LOWCVSS 6.6fixed in vim 2:9.0.1378-1 (bookworm)2023
CVE-2023-1170 [MEDIUM] CVE-2023-1170: vim - Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. Scope: local bookworm: resolved (fixed in 2:9.0.1378-1) bullseye: open forky: resolved (fixed in 2:9.0.1378-1) sid: resolved (fixed in 2:9.0.1378-1) trixie: resolved (fixed in 2:9.0.1378-1)
debian
CVE-2025-24014P4LOWCVSS 4.2fixed in vim 2:9.1.1113-1 (forky)2025
CVE-2025-24014 [MEDIUM] CVE-2025-24014: vim - Vim is an open source, command line text editor. A segmentation fault was found ... Vim is an open source, command line text editor. A segmentation fault was found in Vim before 9.1.1043. In silent Ex mode (-s -e), Vim typically doesn't show a screen and just operates silently in batch mode. However, it is still possible to trigger the function that handles the scrolling of a gui version of Vim by feeding some binary characters to Vim. The function t
debian
CVE-2004-1138P4HIGHCVSS 7.2fixed in vim 1:6.3-046+0sarge1 (bookworm)2004
CVE-2004-1138 [HIGH] CVE-2004-1138: vim - VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary comman... VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu. Scope: local bookworm: resolved (fixed in 1:6.3-046+0sarge
debian
CVE-2026-28418P4MEDIUMCVSS 4.4fixed in vim 2:9.2.0119-1 (forky)2026
CVE-2026-28418 [MEDIUM] CVE-2026-28418: vim - Vim is an open source, command line text editor. Prior to version 9.2.0074, a he... Vim is an open source, command line text editor. Prior to version 9.2.0074, a heap-based buffer overflow out-of-bounds read exists in Vim's Emacs-style tags file parsing logic. When processing a malformed tags file, Vim can be tricked into reading up to 7 bytes beyond the allocated memory boundary. Version 9.2.0074 fixes the issue. Scope: local bookworm: open bullseye
debian
CVE-2025-22134P4LOWCVSS 4.2fixed in vim 2:9.1.1113-1 (forky)2025
CVE-2025-22134 [MEDIUM] CVE-2025-22134: vim - When switching to other buffers using the :all command and visual mode still bei... When switching to other buffers using the :all command and visual mode still being active, this may cause a heap-buffer overflow, because Vim does not properly end visual mode and therefore may try to access beyond the end of a line in a buffer. In Patch 9.1.1003 Vim will correctly reset the visual mode before opening other windows and buffers and therefore fix this b
debian
CVE-2017-17087P4MEDIUMCVSS 5.5fixed in vim 2:8.0.1401-1 (bookworm)2017
CVE-2017-17087 [MEDIUM] CVE-2017-17087: vim - fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the... fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be different from the group ownership of the original file), which allows local users to obtain sensitive information by leveraging an applicable group membership, as demonstrated by /etc/shadow owned by root:shadow mode 0640, but /etc/.shadow.swp owned b
debian
CVE-2024-43790P4LOWCVSS 4.5fixed in vim 2:9.1.0698-1 (forky)2024
CVE-2024-43790 [MEDIUM] CVE-2024-43790: vim - Vim is an open source command line text editor. When performing a search and dis... Vim is an open source command line text editor. When performing a search and displaying the search-count message is disabled (:set shm+=S), the search pattern is displayed at the bottom of the screen in a buffer (msgbuf). When right-left mode (:set rl) is enabled, the search pattern is reversed. This happens by allocating a new buffer. If the search pattern contains s
debian
CVE-2025-53906P4MEDIUMCVSS 4.1fixed in vim 2:9.1.1829-1 (forky)2025
CVE-2025-53906 [MEDIUM] CVE-2025-53906: vim - Vim is an open source, command line text editor. Prior to version 9.1.1551, a pa... Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing execut
debian
CVE-2024-45306P4LOWCVSS 4.5fixed in vim 2:9.1.0709-1 (forky)2024
CVE-2024-45306 [MEDIUM] CVE-2024-45306: vim - Vim is an open source, command line text editor. Patch v9.1.0038 optimized how t... Vim is an open source, command line text editor. Patch v9.1.0038 optimized how the cursor position is calculated and removed a loop, that verified that the cursor position always points inside a line and does not become invalid by pointing beyond the end of a line. Back then we assumed this loop is unnecessary. However, this change made it possible that the cursor pos
debian
CVE-2022-2598P4LOWCVSS 6.5fixed in vim 2:9.0.0135-1 (bookworm)2022
CVE-2022-2598 [MEDIUM] CVE-2022-2598: vim - Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100. Out-of-bounds Write to API in GitHub repository vim/vim prior to 9.0.0100. Scope: local bookworm: resolved (fixed in 2:9.0.0135-1) bullseye: open forky: resolved (fixed in 2:9.0.0135-1) sid: resolved (fixed in 2:9.0.0135-1) trixie: resolved (fixed in 2:9.0.0135-1)
debian
CVE-2023-1175P4MEDIUMCVSS 6.6fixed in vim 2:9.0.1378-1 (bookworm)2023
CVE-2023-1175 [MEDIUM] CVE-2023-1175: vim - Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1... Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378. Scope: local bookworm: resolved (fixed in 2:9.0.1378-1) bullseye: resolved (fixed in 2:8.2.2434-3+deb11u2) forky: resolved (fixed in 2:9.0.1378-1) sid: resolved (fixed in 2:9.0.1378-1) trixie: resolved (fixed in 2:9.0.1378-1)
debian
Debian Vim vulnerabilities | cvebase