Known vulnerabilities in vim (Red Hat package)
Vendor:
Red Hat Inc.
Software:
vim (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:vim_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
54
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
8.0.1763-32.el8_10
9.1.083-9.el10_2.22
8.2.2637-20.el9_2.3
8.2.2637-20.el9_4.4
7.4.629-5.el6_10.4
7.4.629-8.el7_9.2
8.2.2637-26.el9_8.21
8.0.1763-31.el8_10.7
9.1.083-9.el10_2.20
8.2.2637-26.el9_8.13
8.0.1763-31.el8_10
8.0.1763-19.el8_6.6
8.0.1763-20.el8_8.2
8.0.1763-15.el8_4.2
8.0.1763-24.el8_10
9.1.083-9.el10_2.4
8.2.2637-26.el9_8.6
8.2.2637-20.el9_2.2
8.2.2637-22.el9_6.3
8.2.2637-20.el9_4.3
9.1.083-9.el10_2.3
8.2.2637-23.el9_7.3
9.1.083-6.el10_1.4
8.2.2637-23.el9_7.2
9.1.083-6.el10_1.3
8.0.1763-22.el8_10.1
8.0.1763-20.el8_8.1
8.0.1763-19.el8_6.5
8.0.1763-13.el8_2.1
8.0.1763-15.el8_4.1
7.4.629-5.el6_10.3
8.2.2637-16.el9_0.4
7.4.629-8.el7_9.1
8.2.2637-20.el9_4.2
8.2.2637-22.el9_6.2
9.1.083-5.el10_0.2
8.2.2637-23.el9_7.1
8.0.1763-22.el8_10
8.2.2637-22.el9_6
9.1.083-5.el10_0.1
8.2.2637-22.el9_6.1
8.0.1763-21.el8_10
8.2.2637-20.el9_4.1
7.4.629-5.el6_8.1
7.4.160-1.el7_3.1
8.2.2637-21.el9
6.3.046-1.el4_7.5z
7.0.109-4.el5_2.4z
7.0.109-3.el5.3
8.2.2637-20.el9_1
8.0.1763-16.el8
7.4.160-2.el7_4.1
7.4.160-4.el7_5.1
7.4.629-5.el6_10.2
8.0.1763-16.el8_5.4
8.2.2637-16.el9_0.3
8.0.1763-19.el8_6.4
8.2.2637-16.el9_0.2
8.0.1763-16.el8_5.12
8.0.1763-15.el8
8.0.1763-11.el8_0
7.4.629-6.el7
7.4.160-6.el7_6
7.4.160-5.el7
7.4.160-4.el7
7.4.160-2.el7
7.4.160-1.el7_3
7.4.629-5.el6_10
7.4.629-5.el6_8
7.4.629-5.el6
Vulnerabilities (54)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU139392 - Improper Control of Generation of Code ('Code Injection') CVE-2026-73076 |
CWE-94 | High | 7.4.629-8.el7_9.2, 8.0.1763-31.el8_10.7, 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4, 8.2.2637-26.el9_8.21, 9.1.083-9.el10_2.20 | 27.07.2026 |
SB2026072714 SB2026082207 SB2026082208 and 9 more |
||
| #VU139391 - Heap-based Buffer Overflow CVE-2026-73072 |
CWE-122 | Medium | 7.4.629-8.el7_9.2, 8.0.1763-31.el8_10.7, 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4, 8.2.2637-26.el9_8.21, 9.1.083-9.el10_2.20 | 27.07.2026 |
SB2026072713 SB2026082207 SB2026082208 and 9 more |
||
| #VU139390 - Improper Control of Generation of Code ('Code Injection') CVE-2026-73073 |
CWE-94 | High | 8.0.1763-32.el8_10, 9.1.083-9.el10_2.22 | 27.07.2026 |
SB2026072712 SB2026082677 SB2026091342 and 3 more |
||
| #VU139262 - Command injection CVE-2026-73078 |
CWE-77 | High | 7.4.629-8.el7_9.2, 8.0.1763-31.el8_10.7, 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4, 8.2.2637-26.el9_8.21, 9.1.083-9.el10_2.20 | 24.07.2026 |
SB2026072423 SB2026082207 SB2026082208 and 9 more |
||
| #VU139260 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-73077 |
CWE-78 | Medium | 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4, 8.2.2637-26.el9_8.21, 9.1.083-9.el10_2.20 | 24.07.2026 |
SB2026072422 SB2026082207 SB2026082208 and 7 more |
||
| #VU135702 - Improper Control of Generation of Code ('Code Injection') CVE-2026-59856 |
CWE-94 | High | 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4, 8.2.2637-26.el9_8.13 | 29.06.2026 |
SB2026062909 SB20260715103 SB2026072430 and 6 more |
||
| #VU135701 - Improper Control of Generation of Code ('Code Injection') CVE-2026-59858 |
CWE-94 | Medium | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.2, 8.0.1763-31.el8_10, 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4, 8.2.2637-26.el9_8.13 | 29.06.2026 |
SB2026062908 SB20260715103 SB2026072526 and 10 more |
||
| #VU134978 - Improper Control of Generation of Code ('Code Injection') CVE-2026-57456 |
CWE-94 | High | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.2, 8.0.1763-31.el8_10, 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4, 8.2.2637-26.el9_8.13 | 22.06.2026 |
SB2026062216 SB2026070315 SB2026071933 and 7 more |
||
| #VU134977 - Out-of-bounds write CVE-2026-57455 |
CWE-787 | Low | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.2, 8.0.1763-31.el8_10, 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4, 8.2.2637-26.el9_8.13 | 22.06.2026 |
SB2026062215 SB2026070315 SB2026071933 and 7 more |
||
| #VU134580 - Out-of-bounds write CVE-2026-55693 |
CWE-787 | Medium | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.2, 8.0.1763-31.el8_10, 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4, 8.2.2637-26.el9_8.13 | 16.06.2026 |
SB2026061605 SB2026070315 SB2026070617 and 10 more |
||
| #VU133142 - Improper Control of Generation of Code ('Code Injection') CVE-2026-52858 |
CWE-94 | Medium | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.2, 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4 | 01.06.2026 |
SB2026060172 SB20260619120 SB2026062488 and 8 more |
||
| #VU133141 - Out-of-bounds read CVE-2026-52859 |
CWE-125 | Medium | 8.0.1763-31.el8_10.7, 8.2.2637-26.el9_8.21, 9.1.083-9.el10_2.20 | 01.06.2026 |
SB2026060171 SB20260619120 SB2026062488 and 8 more |
||
| #VU131626 - Eval Injection CVE-2026-47167 |
CWE-95 | Medium | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.2, 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4 | 18.05.2026 |
SB2026051807 SB20260619120 SB2026062488 and 7 more |
||
| #VU131625 - Improper Control of Generation of Code ('Code Injection') CVE-2026-47162 |
CWE-94 | Medium | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.2, 8.2.2637-20.el9_2.3, 8.2.2637-20.el9_4.4 | 18.05.2026 |
SB2026051806 SB20260619120 SB2026062488 and 8 more |
||
| #VU131544 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-46483 |
CWE-78 | Low | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.2, 8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3 | 15.05.2026 |
SB2026051517 SB2026052130 SB2026052523 and 23 more |
||
| #VU126870 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-41411 |
CWE-78 | Medium | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.2, 8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.0.1763-24.el8_10, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3, 8.2.2637-26.el9_8.6, 9.1.083-9.el10_2.4 | 22.04.2026 |
SB20260422223 SB2026050840 SB20260509158 and 18 more |
||
| #VU125037 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-34982 |
CWE-78 | High | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.2, 8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3, 8.2.2637-23.el9_7.3, 9.1.083-6.el10_1.4 | 07.04.2026 |
SB2026040792 SB2026041439 SB20260417153 and 15 more |
||
| #VU125036 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-35177 |
CWE-22 | Medium | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.2, 8.0.1763-15.el8_4.2, 8.0.1763-19.el8_6.6, 8.0.1763-20.el8_8.2, 8.2.2637-20.el9_2.2, 8.2.2637-20.el9_4.3, 8.2.2637-22.el9_6.3, 9.1.083-9.el10_2.3 | 07.04.2026 |
SB2026040793 SB2026042846 SB2026050311 and 12 more |
||
| #VU123427 - Heap-based Buffer Overflow CVE-2026-28421 |
CWE-122 | High | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.1, 8.0.1763-13.el8_2.1, 8.0.1763-15.el8_4.1, 8.0.1763-19.el8_6.5, 8.0.1763-20.el8_8.1, 8.0.1763-22.el8_10.1, 8.2.2637-16.el9_0.4, 8.2.2637-20.el9_4.2, 8.2.2637-22.el9_6.2, 8.2.2637-23.el9_7.2, 9.1.083-5.el10_0.2, 9.1.083-6.el10_1.3 | 03.03.2026 |
SB2026030329 SB2026030546 SB2026030620 and 26 more |
||
| #VU123423 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2026-28417 |
CWE-78 | High | 7.4.629-5.el6_10.4, 7.4.629-8.el7_9.1, 8.0.1763-13.el8_2.1, 8.0.1763-15.el8_4.1, 8.0.1763-19.el8_6.5, 8.0.1763-20.el8_8.1, 8.0.1763-22.el8_10.1, 8.2.2637-16.el9_0.4, 8.2.2637-20.el9_4.2, 8.2.2637-22.el9_6.2, 8.2.2637-23.el9_7.2, 9.1.083-5.el10_0.2, 9.1.083-6.el10_1.3 | 03.03.2026 |
SB2026030317 SB2026030620 SB2026030621 and 29 more |
Showing elements 1 - 20 out of 54