Known vulnerabilities in vim (Red Hat package)
Vendor:
Red Hat Inc.
Software:
vim (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:vim_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
42
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
8.2.2637-26.el9_8.13
8.0.1763-31.el8_10
8.0.1763-19.el8_6.6
8.0.1763-20.el8_8.2
8.0.1763-15.el8_4.2
8.0.1763-24.el8_10
9.1.083-9.el10_2.4
8.2.2637-26.el9_8.6
8.2.2637-20.el9_2.2
8.2.2637-22.el9_6.3
8.2.2637-20.el9_4.3
9.1.083-9.el10_2.3
8.2.2637-23.el9_7.3
9.1.083-6.el10_1.4
8.2.2637-23.el9_7.2
9.1.083-6.el10_1.3
8.0.1763-22.el8_10.1
8.0.1763-20.el8_8.1
8.0.1763-19.el8_6.5
8.0.1763-13.el8_2.1
8.0.1763-15.el8_4.1
7.4.629-5.el6_10.3
8.2.2637-16.el9_0.4
7.4.629-8.el7_9.1
8.2.2637-20.el9_4.2
8.2.2637-22.el9_6.2
9.1.083-5.el10_0.2
8.2.2637-23.el9_7.1
8.0.1763-22.el8_10
8.2.2637-22.el9_6
9.1.083-5.el10_0.1
8.2.2637-22.el9_6.1
8.0.1763-21.el8_10
8.2.2637-20.el9_4.1
7.4.629-5.el6_8.1
7.4.160-1.el7_3.1
8.2.2637-21.el9
6.3.046-1.el4_7.5z
7.0.109-4.el5_2.4z
7.0.109-3.el5.3
8.2.2637-20.el9_1
8.0.1763-16.el8
7.4.160-2.el7_4.1
7.4.160-4.el7_5.1
7.4.629-5.el6_10.2
8.0.1763-16.el8_5.4
8.2.2637-16.el9_0.3
8.0.1763-19.el8_6.4
8.2.2637-16.el9_0.2
8.0.1763-16.el8_5.12
8.0.1763-15.el8
8.0.1763-11.el8_0
7.4.629-6.el7
7.4.160-6.el7_6
7.4.160-5.el7
7.4.160-4.el7
7.4.160-2.el7
7.4.160-1.el7_3
7.4.629-5.el6_10
7.4.629-5.el6_8
7.4.629-5.el6
Vulnerabilities (42)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU135702 - Improper Control of Generation of Code ('Code Injection') CVE-2026-59856 |
CWE-94 | High | 8.2.2637-26.el9_8.13 | 29.06.2026 |
SB2026062909 SB20260715103 SB2026072430 and 4 more |
||
| #VU135701 - Improper Control of Generation of Code ('Code Injection') CVE-2026-59858 |
CWE-94 | Medium | 8.0.1763-31.el8_10, 8.2.2637-26.el9_8.13 | 29.06.2026 |
SB2026062908 SB20260715103 SB2026072526 and 5 more |
||
| #VU134978 - Improper Control of Generation of Code ('Code Injection') CVE-2026-57456 |
CWE-94 | High | 8.0.1763-31.el8_10, 8.2.2637-26.el9_8.13 | 22.06.2026 |
SB2026062216 SB2026070315 SB2026071933 and 3 more |
||
| #VU134977 - Out-of-bounds write CVE-2026-57455 |
CWE-787 | Low | 8.0.1763-31.el8_10, 8.2.2637-26.el9_8.13 | 22.06.2026 |
SB2026062215 SB2026070315 SB2026071933 and 3 more |
||
| #VU134580 - Out-of-bounds write CVE-2026-55693 |
CWE-787 | Medium | 8.0.1763-31.el8_10, 8.2.2637-26.el9_8.13 | 16.06.2026 |
SB2026061605 SB2026070315 SB2026070617 and 6 more |
||
| #VU131544 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-46483 |
CWE-78 | Low | 8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3 | 15.05.2026 |
SB2026051517 SB2026052130 SB2026052523 and 20 more |
||
| #VU126870 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-41411 |
CWE-78 | Medium | 8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.0.1763-24.el8_10, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3, 8.2.2637-26.el9_8.6, 9.1.083-9.el10_2.4 | 22.04.2026 |
SB20260422223 SB2026050840 SB20260509158 and 16 more |
||
| #VU125037 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-34982 |
CWE-78 | High | 8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3, 8.2.2637-23.el9_7.3, 9.1.083-6.el10_1.4 | 07.04.2026 |
SB2026040792 SB2026041439 SB20260417153 and 13 more |
||
| #VU125036 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-35177 |
CWE-22 | Medium | 8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3, 9.1.083-9.el10_2.3 | 07.04.2026 |
SB2026040793 SB2026042846 SB2026050311 and 10 more |
||
| #VU124153 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-33412 |
CWE-78 | Medium | 7.4.629-5.el6_10.3, 7.4.629-8.el7_9.1, 8.0.1763-13.el8_2.1, 8.0.1763-15.el8_4.1, 8.0.1763-19.el8_6.5, 8.0.1763-20.el8_8.1, 8.0.1763-22.el8_10.1, 8.2.2637-16.el9_0.4, 8.2.2637-20.el9_4.2, 8.2.2637-22.el9_6.2, 8.2.2637-23.el9_7.2, 9.1.083-5.el10_0.2, 9.1.083-6.el10_1.3 | 20.03.2026 |
SB2026032022 SB20260325108 SB20260325109 and 23 more |
||
| #VU123427 - Heap-based Buffer Overflow CVE-2026-28421 |
CWE-122 | High | 7.4.629-8.el7_9.1, 8.0.1763-13.el8_2.1, 8.0.1763-15.el8_4.1, 8.0.1763-19.el8_6.5, 8.0.1763-20.el8_8.1, 8.0.1763-22.el8_10.1, 8.2.2637-16.el9_0.4, 8.2.2637-20.el9_4.2, 8.2.2637-22.el9_6.2, 8.2.2637-23.el9_7.2, 9.1.083-5.el10_0.2, 9.1.083-6.el10_1.3 | 03.03.2026 |
SB2026030329 SB2026030546 SB2026030620 and 25 more |
||
| #VU123423 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-28417 |
CWE-78 | High | 7.4.629-8.el7_9.1, 8.0.1763-13.el8_2.1, 8.0.1763-15.el8_4.1, 8.0.1763-19.el8_6.5, 8.0.1763-20.el8_8.1, 8.0.1763-22.el8_10.1, 8.2.2637-16.el9_0.4, 8.2.2637-20.el9_4.2, 8.2.2637-22.el9_6.2, 8.2.2637-23.el9_7.2, 9.1.083-5.el10_0.2, 9.1.083-6.el10_1.3 | 03.03.2026 |
SB2026030317 SB2026030620 SB2026030621 and 28 more |
||
| #VU122421 - Heap-based Buffer Overflow CVE-2026-25749 |
CWE-122 | High | 7.4.629-8.el7_9.1, 8.0.1763-13.el8_2.1, 8.0.1763-15.el8_4.1, 8.0.1763-19.el8_6.5, 8.0.1763-20.el8_8.1, 8.0.1763-22.el8_10, 8.2.2637-16.el9_0.4, 8.2.2637-20.el9_4.2, 8.2.2637-22.el9_6.2, 8.2.2637-23.el9_7.1, 9.1.083-5.el10_0.2 | 05.02.2026 |
SB2026020601 SB2026021309 SB2026021310 and 19 more |
||
| #VU112980 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-53905 |
CWE-22 | High | 8.0.1763-21.el8_10, 8.2.2637-20.el9_4.1, 8.2.2637-22.el9_6.1, 9.1.083-5.el10_0.1 | 16.07.2025 |
SB2025071691 SB2025071770 SB2025071771 and 23 more |
||
| #VU112979 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-53906 |
CWE-22 | High | 8.0.1763-21.el8_10, 8.2.2637-20.el9_4.1, 8.2.2637-22.el9_6.1, 9.1.083-5.el10_0.1 | 16.07.2025 |
SB2025071690 SB2025071770 SB2025071771 and 29 more |
||
| #VU71559 - NULL Pointer Dereference CVE-2022-47024 |
CWE-476 | Low | 8.2.2637-20.el9_1 | 26.01.2023 |
SB2023012623 SB2023013121 SB2023022848 and 16 more |
||
| #VU64508 - Out-of-bounds read CVE-2022-1927 |
CWE-125 | Low | 8.0.1763-19.el8_6.4, 8.2.2637-16.el9_0.3 | 20.06.2022 |
SB2022062022 SB2022080332 SB2022080610 and 49 more |
||
| #VU64506 - Out-of-bounds write CVE-2022-1897 |
CWE-787 | Low | 8.0.1763-19.el8_6.4, 8.2.2637-16.el9_0.3 | 20.06.2022 |
SB2022062022 SB2022070807 SB2022080332 and 48 more |
||
| #VU63487 - Out-of-bounds write CVE-2022-1785 |
CWE-787 | High | 8.0.1763-19.el8_6.4, 8.2.2637-16.el9_0.3 | 20.05.2022 |
SB2022052017 SB2022062022 SB2022063027 and 47 more |
||
| #VU63060 - Heap-based Buffer Overflow CVE-2021-3903 |
CWE-122 | High | 8.2.2637-21.el9 | 11.05.2022 |
SB2022051173 SB2021111514 SB2022062022 and 39 more |
Showing elements 1 - 20 out of 42