CVE-2026-73075
Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the screen array instead of accounting for w_popup_topoff and causing an out-of-bounds read and conditional write. This issue is fixed in version 9.2.0843.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.6
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.12%
- CWE
- CWE-124, CWE-125
- Published
- 2026-08-11
- Last modified
- 2026-08-11
Affected products
- vim vim
Weakness type
Related vulnerabilities
- CVE-2026-40013 — An attacker that has valid credentials can submit a Sieve script containing an extreme numeric...
- CVE-2026-71969 — OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
- CVE-2026-16439 — Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow
- CVE-2026-26199 — Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero
- CVE-2026-44631 — Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow
- CVE-2024-36343 — Improper input validation in the System Management Mode (SMM) communications buffer could allow a...
- CVE-2026-5089 — YAML::Syck versions before 1.38 for Perl has an out-of-bounds read
- CVE-2026-41499 — Wazuh: Multiple Heap-based NULL WRITE Buffer Underflows in parse_uname_string()