Vim是Vim组织开源的一款高效的文本编辑器。 Vim 9.2.0842之前版本存在缓冲区错误漏洞,该漏洞源于src/socketserver.c中的socketserver_accept()函数接受无限制的客户端连接,导致描述符溢出fd_set结构和固定大小的pollfd数组,可能允许本地进程连接服务器套接字,破坏栈内存或终止Vim服务器。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73078 | 8.6 HIGH | Vim: Arbitrary Code Execution via Netrw Menu Construction |
| CVE-2026-73072 | 8.5 HIGH | Vim: Heap Buffer Overflow when Loading a Spell File |
| CVE-2026-73076 | 8.4 HIGH | Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.v |
| CVE-2026-73077 | 8.4 HIGH | Vim: Arbitrary Code Execution via Shell Keyword Lookup |
| CVE-2026-73074 | 7.1 HIGH | Vim: Heap Buffer Overflow in Text Property Handling |
| CVE-2026-73075 | 4.6 MEDIUM | Vim: Out-of-bounds Access in Popup Opacity Handling |
| CVE-2026-73071 | 3.3 LOW | Vim: Use-after-free in JSON Decoding |
No comments yet