Vim CVE Vulnerabilities & CVE List (248)

Products (CPE): — CVEs: 248

Vim vulnerability overview

Aggregates CVE and security vulnerability intelligence across all Vim-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk buffer overflow, vendor risk input validation, and vendor risk path handling; exposure may include vendor impact memory corruption in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 81100 of 248 CVEs
«« First « Prev Page 5 / 13 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-1355 NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1402. [email protected] 5.5 0.45% 2023-03-11 2026-06-17
CVE-2023-1264 NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392. [email protected] 5.5 0.43% 2023-03-07 2026-06-17
CVE-2023-1175 Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378. [email protected] 6.6 0.44% 2023-03-04 2026-06-17
CVE-2023-1170 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. [email protected] 6.6 0.48% 2023-03-03 2026-06-17
CVE-2023-1127 Divide By Zero in GitHub repository vim/vim prior to 9.0.1367. [email protected] 7.8 0.46% 2023-03-01 2026-06-17
CVE-2023-0512 Divide By Zero in GitHub repository vim/vim prior to 9.0.1247. [email protected] 7.8 0.49% 2023-01-30 2026-06-17
CVE-2023-0433 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1225. [email protected] 7.8 0.56% 2023-01-21 2026-06-17
CVE-2022-47024 A null pointer dereference issue was discovered in function gui_x11_create_blank_mouse in gui_x11.c in vim 8.1.2269 thru 9.0.0339 allows attackers to cause denial of service or other unspecified impacts. [email protected] 7.8 0.26% 2023-01-20 2026-06-17
CVE-2023-0288 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1189. [email protected] 7.8 0.47% 2023-01-13 2026-06-17
CVE-2023-0054 Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.1145. [email protected] 7.8 0.47% 2023-01-04 2026-06-17
CVE-2023-0051 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1144. [email protected] 7.8 0.52% 2023-01-04 2026-06-17
CVE-2023-0049 Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. [email protected] 7.8 0.47% 2023-01-04 2026-06-17
CVE-2022-4293 Floating Point Comparison with Incorrect Operator in GitHub repository vim/vim prior to 9.0.0804. [email protected] 5.5 0.46% 2022-12-05 2026-06-17
CVE-2022-4292 Use After Free in GitHub repository vim/vim prior to 9.0.0882. [email protected] 7.8 0.66% 2022-12-05 2026-06-17
CVE-2022-3491 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0742. [email protected] 7.8 0.50% 2022-12-03 2026-06-17
CVE-2022-3520 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0765. [email protected] 9.8 1.00% 2022-12-02 2026-06-17
CVE-2022-3591 Use After Free in GitHub repository vim/vim prior to 9.0.0789. [email protected] 7.8 0.37% 2022-12-02 2026-06-17
CVE-2022-4141 Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command. [email protected] 7.8 0.42% 2022-11-25 2026-06-17
CVE-2022-3705 A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version 9.0.0805 is able to address this issue. The name of the patch is d0fab10ed2a86698937e3c3fed2f10bd9bb5e731. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-212324. [email protected] 5.0 1.20% 2022-10-26 2026-06-17
CVE-2022-3352 Use After Free in GitHub repository vim/vim prior to 9.0.0614. [email protected] 7.8 0.49% 2022-09-29 2026-06-17
«« First « Prev Page 5 / 13 Next »
cvelogic Threat Intelligence