Vim是Vim组织开源的一款高效的文本编辑器。 Vim 9.2.0846之前版本存在缓冲区错误漏洞,该漏洞源于set_sofo()函数重用sl_sal_first[]未重置set_sal_first()留下的值,导致特制拼写文件可造成映射列表计数不足和堆分配之外的写入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-73078 | 8.6 HIGH | Vim: Arbitrary Code Execution via Netrw Menu Construction |
| CVE-2026-73076 | 8.4 HIGH | Vim: Arbitrary Command Execution via Malicious `.VimballRecord` Entry Replay in `vimball.v |
| CVE-2026-73077 | 8.4 HIGH | Vim: Arbitrary Code Execution via Shell Keyword Lookup |
| CVE-2026-73074 | 7.1 HIGH | Vim: Heap Buffer Overflow in Text Property Handling |
| CVE-2026-73070 | 6.8 MEDIUM | Vim: Stack Buffer Overflow in the Vim Socket Server |
| CVE-2026-73075 | 4.6 MEDIUM | Vim: Out-of-bounds Access in Popup Opacity Handling |
| CVE-2026-73071 | 3.3 LOW | Vim: Use-after-free in JSON Decoding |
No comments yet