Vim是Vim组织开源的一款跨平台的文本编辑器。 Vim 9.2.0653之前版本存在缓冲区错误漏洞,该漏洞源于tree_count_words()函数在src/spellfile.c中未检查深度计数器与固定栈数组边界,导致堆栈越界写入,可能使攻击者通过特制.spl/.sug文件对编辑器造成崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57453 | 6.5 MEDIUM | Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction |
| CVE-2026-57452 | 5.5 MEDIUM | Vim: Out-of-bounds Read with libsodium-encrypted Files |
| CVE-2026-55892 | 5.5 MEDIUM | Vim: Out-of-bounds Write in Spell File Prefix Dump |
| CVE-2026-57451 | 5.3 MEDIUM | Vim: Out-of-bounds Read in Text Property Count |
| CVE-2026-57456 | Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings | |
| CVE-2026-57455 | Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold() | |
| CVE-2026-57454 | Vim: Out-of-bounds Read with Text Properties | |
| CVE-2026-55895 | Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename |
No comments yet