Christian Brabandt
64 exploits
Active since Sep 2023
Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name
CVSS 8.8
Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex
CVSS 5.3
Vim: Arbitrary Code Execution via Python Omni-Completion
CVSS 7.8
Vim: Out-of-bounds Read in Terminal Screen Snapshot
CVSS 8.2
Vim: Arbitrary Code Execution via Python Omni-Completion
CVSS 7.8
Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag
CVSS 3.6
Vim netrw - OS Command Injection
CVSS 4.4
Vim path Completion - OS Command Injection
CVSS 5.3
Vim: Heap Buffer Overflow in spell file loading
CVSS 6.6
Vim 9.1.0858-9.1.1163 - Command Injection via tar.vim Plugin
CVSS 7.1
Vim < 9.2.0357 - OS Command Injection via Tag File Processing
CVSS 6.6
Vim Ex command injection in Vims NetBeans integration
CVSS 5.0
Vim modeline bypass via various options affects Vim < 9.2.0276
CVSS 8.2
Vim < 9.2.0272 - Remote Code Execution via %{expr} Injection in Tabpanel
CVSS 9.2
Vim affected by Command injection via newline in glob()
CVSS 5.6
Vim 9.1.0011-9.2.0137 - Memory Corruption
CVSS 5.3
Vim < 9.2.0073 - OS Command Injection via netrw Plugin SCP URL Handler
CVSS 4.4
Vim < 9.2.0074 - Heap-based Buffer Overflow in Emacs-style Tags File Parser
CVSS 4.4
vim < 9.2.0075 - Heap-Based Buffer Underflow in Emacs-Style Tags File Parser
CVSS 5.3
Vim < 9.2.0076 - Heap-based Buffer Overflow in Terminal Emulator
CVSS 4.4
Vim < 9.2.0077 - Heap Buffer Overflow and Denial of Service via Swap File Recovery
CVSS 5.3
vim < 9.2.0078 - Stack-based Buffer Overflow in Statusline Rendering
CVSS 2.2
vim < 9.0.2068 - Use-After-Free via Integer Overflow in History Command
CVSS 4.0
macOS < 14.1 - Use-After-Free
CVSS 7.8
vim < 9.0.1846 - Integer Overflow or Wraparound
CVSS 7.8