Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

vim — Vulnerabilities & Security Advisories 203

Browse all 203 CVE security advisories affecting vim. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Vim is a widely used, open-source text editor primarily designed for efficient code editing and system administration tasks across Unix-like operating systems. Despite its utility, the software has accumulated approximately 200 Common Vulnerabilities and Exposures (CVEs), reflecting its complex codebase and long history. Historically, these security flaws have predominantly involved remote code execution (RCE) and buffer overflow vulnerabilities, often triggered by malformed files or specific command-line arguments. While cross-site scripting is irrelevant to its terminal-based nature, privilege escalation risks have occasionally arisen through improper file permission handling or setuid configurations. Notable incidents include critical RCE flaws in the ex command interpreter and memory corruption issues within the clipboard handling subsystem. These vulnerabilities underscore the importance of keeping the editor updated, as attackers frequently exploit parsing errors to gain unauthorized system access or execute arbitrary code within the user’s environment.

Found 159 results / 203Clear Filters
Top products by vim: vim/vim vim
CVE IDTitleCVSSSeverityPublished
CVE-2022-0554 Use of Out-of-range Pointer Offset in vim/vim — vim/vimCWE-823 7.8 -2022-02-10
CVE-2022-0443 Use After Free in vim/vim — vim/vimCWE-416 7.8 -2022-02-02
CVE-2022-0417 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2022-02-01
CVE-2022-0407 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2022-01-30
CVE-2022-0408 Stack-based Buffer Overflow in vim/vim — vim/vimCWE-121 7.8 -2022-01-30
CVE-2022-0413 Use After Free in vim/vim — vim/vimCWE-416 7.8 -2022-01-30
CVE-2022-0393 Out-of-bounds Read in vim/vim — vim/vimCWE-125 7.8 -2022-01-28
CVE-2022-0392 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2022-01-28
CVE-2022-0359 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2022-01-26
CVE-2022-0361 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2022-01-26
CVE-2022-0368 Out-of-bounds Read in vim/vim — vim/vimCWE-125 7.8 -2022-01-26
CVE-2022-0351 Access of Memory Location Before Start of Buffer in vim/vim — vim/vimCWE-786 7.8 -2022-01-25
CVE-2022-0318 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2022-01-21
CVE-2022-0319 Out-of-bounds Read in vim/vim — vim/vimCWE-125 7.1 -2022-01-21
CVE-2022-0261 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2022-01-18
CVE-2022-0213 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2022-01-14
CVE-2022-0156 Use After Free in vim/vim — vim/vimCWE-416 7.8 -2022-01-10
CVE-2022-0158 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2022-01-10
CVE-2022-0128 Out-of-bounds Read in vim/vim — vim/vimCWE-125 7.8 -2022-01-06
CVE-2021-4192 Use After Free in vim/vim — vim/vimCWE-416 7.8 -2021-12-31
CVE-2021-4193 Out-of-bounds Read in vim/vim — vim/vimCWE-125 7.8 -2021-12-31
CVE-2021-4187 Use After Free in vim/vim — vim/vimCWE-416 7.8 -2021-12-29
CVE-2021-4173 Use After Free in vim/vim — vim/vimCWE-416 7.8 -2021-12-27
CVE-2021-4166 Out-of-bounds Read in vim/vim — vim/vimCWE-125 7.8 -2021-12-25
CVE-2021-4136 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2021-12-19
CVE-2021-4069 Use After Free in vim/vim — vim/vimCWE-416 7.8 -2021-12-06
CVE-2021-3984 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2021-12-01
CVE-2021-4019 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2021-12-01
CVE-2021-3968 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2021-11-19
CVE-2021-3973 Heap-based Buffer Overflow in vim/vim — vim/vimCWE-122 7.8 -2021-11-19

This page lists every published CVE security advisory associated with vim. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.