Threats Tagged 'cve-2026-73077'
View all threats tagged with 'cve-2026-73077'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-73077'
Click on any threat for detailed analysis and mitigation recommendations
0 Multiple security vulnerabilities have been identified in Vim (Vi IMproved), including several that allow arbitrary code execution via crafted inputs such as directory names, Python omni-completion, PHP files, tags files, vimball files, and insecure shell command handling. Additionally, there are vulnerabilities leading to denial of service via stack out-of-bounds writes and out-of-bounds writes in spell file word counts. These issues affect Red Hat Enterprise Linux 10.0 Extended Update Support and related packages. Red Hat has issued security advisories and updates addressing these vulnerabilities. Join the discussion | GCVE Database | 09/28/2026, 12:17:49 UTC Added: 06/13/2026, 10:23:12 UTC |
Red Hat Update Infrastructure (RHUI) container images are based on the latest RHUI RPM packages and the ubi9 or ubi9-init base images. This release updates to the latest version. Join the discussion | GCVE Database | 09/16/2026, 10:07:58 UTC Added: 07/16/2026, 10:39:53 UTC |
0 Vim (Vi IMproved) is an updated and improved version of the vi editor. Security Fix(es): * vim: Vim: Information disclosure and denial of service via crafted Unicode characters in terminal emulator (CVE-2026-28420) * vim: Vim: Denial of Service via out-of-bounds write in terminal handling (CVE-2026-52859) * vim: Vim: Denial of Service via crafted spell file (CVE-2026-55892) * vim: Vim: Denial of Service via out-of-bounds write in spell sound-folding (CVE-2026-59857) * vim: Vim: Arbitrary command execution via crafted vimball (CVE-2026-73076) * vim: Vim: Heap buffer overflow allows arbitrary code execution (CVE-2026-73072) * vim: Vim: Arbitrary Code Execution via Crafted Netrw Menu Entries (CVE-2026-73078) * vim: Vim: Arbitrary Code Execution via Insecure Shell Command Handling (CVE-2026-73077) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/10/2026, 13:18:14 UTC Added: 09/10/2026, 13:23:36 UTC |
0 Multiple security vulnerabilities affecting Vim version 9.2.0957 have been fixed in this update. These include stack buffer overflow, use-after-free, heap buffer overflows, out-of-bounds access, and arbitrary code execution issues. The vulnerabilities can lead to denial of service, process crashes, or potential arbitrary code execution. The update addresses these issues by upgrading to version 9.2.0957. Additional bug fixes and improvements unrelated to security are also included. Join the discussion | GCVE Database | 08/28/2026, 08:29:35 UTC Added: 08/23/2026, 13:46:09 UTC |
Vim versions prior to 9.2.0839 contain a vulnerability in certain runtime filetype plugins that improperly handle attacker-controlled Visual-mode selections. This flaw allows shell metacharacters to be passed unsafely to shell commands, enabling arbitrary command execution with the privileges of the user running Vim. The issue affects multiple Ubuntu package versions of Vim and is fixed in version 9.2.0839. Join the discussion | GCVE Database | 08/11/2026, 16:17:00 UTC Added: 08/20/2026, 14:08:54 UTC |
Multiple vulnerabilities have been identified in Vim (Vi IMproved), affecting all versions up to and including 9.2.0662. No specific technical details or CVE identifiers are provided beyond references to several CVEs. There are no known exploits in the wild at this time, and no patch or remediation information is currently available. Join the discussion | GCVE Database | 07/26/2026, 22:00:00 UTC Added: 06/17/2026, 16:49:01 UTC |
Showing 1 to 6 of 6 results