Vim-8.1 : Remote attackers can execute arbitrary OS commands via the :source! command in a modeline in all versions of vim before 8.1.1365. Fixed in the development book and in the BLFS development book.
Linux Kernel: remotely exploitable kernel panic via the TCP stack (SACK PANIC) in all versions of Linux from 2.6.x on up. Fixed in the development book.