vim development group records
8 published records for vendor vim development group.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 75%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2005-2368No exploit | vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharactevim development group · vim · CWE-78 | Critical9.3 | — | 2.7% | Jul 26, 2005 |
31Monitor | CVE-2007-2438No exploit | The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackerforesight linux · foresight linux | High7.6 | — | 3.2% | May 2, 2007 |
28Monitor | CVE-2007-2953No exploit | Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted revim development group · vim | Medium6.8 | — | 4.2% | Jul 31, 2007 |
28Monitor | CVE-2004-1138No exploit | VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executedvim development group · vim | High7.2 | — | 0.4% | Jan 10, 2005 |
21Monitor | CVE-2001-0408No exploit | vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when anothvim development group · vim | Medium5.1 | — | 1.7% | Jun 18, 2001 |
18Monitor | CVE-2002-1377No exploit | vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which avim development group · vim | Medium4.6 | — | 0.5% | Dec 23, 2002 |
18Monitor | CVE-2005-0069No exploit | The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on tempovim development group · vim | Medium4.6 | — | 0.4% | Jan 13, 2005 |
8Monitor | CVE-2001-0409Proof of concept | vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the vivim development group · vim | Low2.1 | — | 0.7% | Jun 18, 2001 |
- CVE-2005-236838Monitor
vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacte
CriticalCVSS 9.3No exploitEPSS 3%vim development group · vimJul 26, 2005
- CVE-2007-243831Monitor
The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attacker
HighCVSS 7.6No exploitEPSS 3%foresight linux · foresight linuxMay 2, 2007
- CVE-2007-295328Monitor
Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted re
MediumCVSS 6.8No exploitEPSS 4%vim development group · vimJul 31, 2007
- CVE-2004-113828Monitor
VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed
HighCVSS 7.2No exploitEPSS 0%vim development group · vimJan 10, 2005
- CVE-2001-040821Monitor
vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when anoth
MediumCVSS 5.1No exploitEPSS 2%vim development group · vimJun 18, 2001
- CVE-2002-137718Monitor
vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which a
MediumCVSS 4.6No exploitEPSS 0%vim development group · vimDec 23, 2002
- CVE-2005-006918Monitor
The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on tempo
MediumCVSS 4.6No exploitEPSS 0%vim development group · vimJan 13, 2005
- CVE-2001-04098Monitor
vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the vi
LowCVSS 2.1Proof of conceptEPSS 1%vim development group · vimJun 18, 2001