Vim是Vim组织开源的一款跨平台的文本编辑器。 Vim 9.2.0662之前版本存在缓冲区错误漏洞,该漏洞源于dump_prefixes()函数在遍历拼写文件前缀树时,深度计数器仅受树结构自身限制,未检查固定大小栈数组的索引边界,导致栈越界写入,可能破坏调用帧并导致编辑器崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57453 | 6.5 MEDIUM | Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction |
| CVE-2026-57452 | 5.5 MEDIUM | Vim: Out-of-bounds Read with libsodium-encrypted Files |
| CVE-2026-57451 | 5.3 MEDIUM | Vim: Out-of-bounds Read in Text Property Count |
| CVE-2026-57456 | Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings | |
| CVE-2026-57455 | Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold() | |
| CVE-2026-57454 | Vim: Out-of-bounds Read with Text Properties | |
| CVE-2026-55895 | Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename | |
| CVE-2026-55693 | Vim: Out-of-bounds Write in Spell File Word Count |
No comments yet