<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 16:12:01 +0000</lastBuildDate>
    <item>
      <title>bdu:2024-07097</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-07097</link>
      <description>bdu:2024-07097</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-07097</guid>
    </item>
    <item>
      <title>BELL-CVE-2024-43374</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2024-43374</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: vim, Alpaquita:stream: vim&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: vim, Alpaquita:stream: vim&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2024-43374</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0585 — De multiples vulnérabilités ont été découvertes dans VMware Tanzu. Certaines d'entre elles permettent à un attaquant de…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0585</link>
      <description>certfr-2025-avi-0585</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0585</guid>
    </item>
    <item>
      <title>cnvd-2024-40461</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2024-40461</link>
      <description>cnvd-2024-40461</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2024-40461</guid>
    </item>
    <item>
      <title>EUVD-2026-186958</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-186958</link>
      <description>EUVD-2026-186958</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-186958</guid>
    </item>
    <item>
      <title>fkie_cve-2024-43374</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-43374</link>
      <description>&lt;p&gt;The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this causes the window structure to be freed which contains a reference to the argument list that we are actually modifying. Once the autocommands are completed, the references to the window and argument list are no longer valid and as such cause an use-after-free. Impact is low since the user must either intentionally add some unusual autocommands that wipe a buffer during creation (either manually or by sourcing a malicious plugin), but it will crash Vim. The issue has been fixed as of Vim patch v9.1.0678.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this causes the window structure to be freed which contains a reference to the argument list that we are actually modifying. Once the autocommands are completed, the references to the window and argument list are no longer valid and as such cause an use-after-free. Impact is low since the user must either intentionally add some unusual autocommands that wipe a buffer during creation (either manually or by sourcing a malicious plugin), but it will crash Vim. The issue has been fixed as of Vim patch v9.1.0678.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-43374</guid>
    </item>
    <item>
      <title>msrc_CVE-2024-43374 — Vim heap-use-after-free in src/arglist.c:207</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2024-43374</link>
      <description>msrc_CVE-2024-43374</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2024-43374</guid>
    </item>
    <item>
      <title>OESA-2024-2026 — vim security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-2026</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: vim, openEuler:24.03-LTS: vim, openEuler:22.03-LTS-SP4: vim, openEuler:22.03-LTS-SP3: vim, openEuler:20.03-LTS-SP4: vim&lt;/p&gt;
&lt;p&gt;Vim is an advanced text editor that seeks to provide the power of the de-facto Unix editor &amp;amp;apos;Vi&amp;amp;apos;, with a more complete feature set. Vim is a highly configurable text editor built to enable efficient text editing. It is an improved version of the vi editor distributed with most UNIX systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this causes the window structure to be freed which contains a reference to the argument list that we are actually modifying. Once the autocommands are completed, the references to the window and argument list are no longer valid and as such cause an use-after-free. Impact is low since the user must either intentionally add some unusual autocommands that wipe a buffer during creation (either manually or by sourcing a malicious plugin), but it will crash Vim. The issue has been fixed as of Vim patch v9.1.0678.(CVE-2024-43374)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP1: vim, openEuler:24.03-LTS: vim, openEuler:22.03-LTS-SP4: vim, openEuler:22.03-LTS-SP3: vim, openEuler:20.03-LTS-SP4: vim&lt;/p&gt;
&lt;p&gt;Vim is an advanced text editor that seeks to provide the power of the de-facto Unix editor &amp;amp;apos;Vi&amp;amp;apos;, with a more complete feature set. Vim is a highly configurable text editor built to enable efficient text editing. It is an improved version of the vi editor distributed with most UNIX systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this causes the window structure to be freed which contains a reference to the argument list that we are actually modifying. Once the autocommands are completed, the references to the window and argument list are no longer valid and as such cause an use-after-free. Impact is low since the user must either intentionally add some unusual autocommands that wipe a buffer during creation (either manually or by sourcing a malicious plugin), but it will crash Vim. The issue has been fixed as of Vim patch v9.1.0678.(CVE-2024-43374)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-2026</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:4330-1 — Security update for vim</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:4330-1</link>
      <description>&lt;p&gt;Security update for vim&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for vim&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:4330-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-43374</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-43374</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: vim, Ubuntu:Pro:16.04:LTS: vim, Ubuntu:Pro:18.04:LTS: vim, Ubuntu:20.04:LTS: vim, Ubuntu:22.04:LTS: vim, Ubuntu:24.04:LTS: vim&lt;/p&gt;
&lt;p&gt;The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this causes the window structure to be freed which contains a reference to the argument list that we are actually modifying. Once the autocommands are completed, the references to the window and argument list are no longer valid and as such cause an use-after-free. Impact is low since the user must either intentionally add some unusual autocommands that wipe a buffer during creation (either manually or by sourcing a malicious plugin), but it will crash Vim. The issue has been fixed as of Vim patch v9.1.0678.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: vim, Ubuntu:Pro:16.04:LTS: vim, Ubuntu:Pro:18.04:LTS: vim, Ubuntu:20.04:LTS: vim, Ubuntu:22.04:LTS: vim, Ubuntu:24.04:LTS: vim&lt;/p&gt;
&lt;p&gt;The UNIX editor Vim prior to version 9.1.0678 has a use-after-free error in argument list handling. When adding a new file to the argument list, this triggers `Buf*` autocommands. If in such an autocommand the buffer that was just opened is closed (including the window where it is shown), this causes the window structure to be freed which contains a reference to the argument list that we are actually modifying. Once the autocommands are completed, the references to the window and argument list are no longer valid and as such cause an use-after-free. Impact is low since the user must either intentionally add some unusual autocommands that wipe a buffer during creation (either manually or by sourcing a malicious plugin), but it will crash Vim. The issue has been fixed as of Vim patch v9.1.0678.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-43374</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1870 — vim: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1870</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in vim ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann eine Schwachstelle in vim ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1870</guid>
    </item>
  </channel>
</rss>
