Aggregates CVE and security vulnerability intelligence across all Vim-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Disclosed issues often relate to vendor risk buffer overflow, vendor risk input validation, and vendor risk path handling; exposure may include vendor impact memory corruption in vendor surface production workloads contexts.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-1355 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1402. | [email protected] | 5.5 | 0.45% | 2023-03-11 | 2026-06-17 |
| CVE-2023-1264 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392. | [email protected] | 5.5 | 0.43% | 2023-03-07 | 2026-06-17 |
| CVE-2023-1175 | Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378. | [email protected] | 6.6 | 0.44% | 2023-03-04 | 2026-06-17 |
| CVE-2023-1170 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. | [email protected] | 6.6 | 0.48% | 2023-03-03 | 2026-06-17 |
| CVE-2023-1127 | Divide By Zero in GitHub repository vim/vim prior to 9.0.1367. | [email protected] | 7.8 | 0.46% | 2023-03-01 | 2026-06-17 |
| CVE-2023-0512 | Divide By Zero in GitHub repository vim/vim prior to 9.0.1247. | [email protected] | 7.8 | 0.49% | 2023-01-30 | 2026-06-17 |
| CVE-2023-0433 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. | [email protected] | 7.8 | 0.56% | 2023-01-21 | 2026-06-17 |
| CVE-2022-47024 | A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts. | [email protected] | 7.8 | 0.26% | 2023-01-20 | 2026-06-17 |
| CVE-2023-0288 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189. | [email protected] | 7.8 | 0.47% | 2023-01-13 | 2026-06-17 |
| CVE-2023-0054 | Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145. | [email protected] | 7.8 | 0.47% | 2023-01-04 | 2026-06-17 |
| CVE-2023-0051 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144. | [email protected] | 7.8 | 0.52% | 2023-01-04 | 2026-06-17 |
| CVE-2023-0049 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. | [email protected] | 7.8 | 0.47% | 2023-01-04 | 2026-06-17 |
| CVE-2022-4293 | Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804. | [email protected] | 5.5 | 0.46% | 2022-12-05 | 2026-06-17 |
| CVE-2022-4292 | Use After Free in GitHub repository vim/vim prior to 9.0.0882. | [email protected] | 7.8 | 0.66% | 2022-12-05 | 2026-06-17 |
| CVE-2022-3491 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742. | [email protected] | 7.8 | 0.50% | 2022-12-03 | 2026-06-17 |
| CVE-2022-3520 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765. | [email protected] | 9.8 | 1.00% | 2022-12-02 | 2026-06-17 |
| CVE-2022-3591 | Use After Free in GitHub repository vim/vim prior to 9.0.0789. | [email protected] | 7.8 | 0.37% | 2022-12-02 | 2026-06-17 |
| CVE-2022-4141 | Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command. | [email protected] | 7.8 | 0.42% | 2022-11-25 | 2026-06-17 |
| CVE-2022-3705 | A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version 9.0.0805 is able to address this issue. The name of the patch is d0fab10ed2a86698937e3c3fed2f10bd9bb5e731. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-212324. | [email protected] | 5.0 | 1.20% | 2022-10-26 | 2026-06-17 |
| CVE-2022-3352 | Use After Free in GitHub repository vim/vim prior to 9.0.0614. | [email protected] | 7.8 | 0.49% | 2022-09-29 | 2026-06-17 |