Skip to content
Noroxi

vim development group records

8 published records for vendor vim development group.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
75%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    8 records
    • CVE-2005-2368
      38Monitor

      vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacte

      CriticalCVSS 9.3No exploitEPSS 3%

      vim development group · vimJul 26, 2005

    • CVE-2007-2438
      31Monitor

      The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attacker

      HighCVSS 7.6No exploitEPSS 3%

      foresight linux · foresight linuxMay 2, 2007

    • CVE-2007-2953
      28Monitor

      Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted re

      MediumCVSS 6.8No exploitEPSS 4%

      vim development group · vimJul 31, 2007

    • CVE-2004-1138
      28Monitor

      VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed

      HighCVSS 7.2No exploitEPSS 0%

      vim development group · vimJan 10, 2005

    • CVE-2001-0408
      21Monitor

      vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when anoth

      MediumCVSS 5.1No exploitEPSS 2%

      vim development group · vimJun 18, 2001

    • CVE-2002-1377
      18Monitor

      vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which a

      MediumCVSS 4.6No exploitEPSS 0%

      vim development group · vimDec 23, 2002

    • CVE-2005-0069
      18Monitor

      The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on tempo

      MediumCVSS 4.6No exploitEPSS 0%

      vim development group · vimJan 13, 2005

    • vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the vi

      LowCVSS 2.1Proof of conceptEPSS 1%

      vim development group · vimJun 18, 2001