A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-2085 A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component.
Ubuntu USN Ubuntu USN USN-7419-1 Vim vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 14 Aug 2025 02:30:00 +0900

Type Values Removed Values Added
First Time appeared Netapp
Netapp bootstrap Os
CPEs cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
cpe:2.3:o:netapp:bootstrap_os:-:*:*:*:*:*:*:*
Vendors & Products Netapp
Netapp bootstrap Os

Wed, 16 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00024}

epss

{'score': 0.00025}


Sat, 12 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00022}

epss

{'score': 0.00024}


Fri, 11 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00041}

epss

{'score': 0.00022}


Sat, 22 Mar 2025 03:45:00 +0900

Type Values Removed Values Added
References

Thu, 13 Feb 2025 10:45:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Thu, 13 Feb 2025 05:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 03:45:00 +0900

Type Values Removed Values Added
Description A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component.
Title vim main.c memory corruption
Weaknesses CWE-119
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P'}

cvssV3_0

{'score': 2.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-03-21T18:03:50.360Z

Reserved: 2025-02-10T22:55:47.747Z

Link: CVE-2025-1215

cve-icon Vulnrichment

Updated: 2025-03-21T18:03:50.360Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-12T19:15:10.230

Modified: 2025-08-13T17:28:19.607

Link: CVE-2025-1215

cve-icon Redhat

Severity : Low

Publid Date: 2025-02-12T18:31:06Z

Links: CVE-2025-1215 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T20:07:24Z

Weaknesses