rpm package
opensuse/vim&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/vim&distro=openSUSE%20Tumbleweed
Vulnerabilities (125)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-6349 | Cri | 9.8 | < 8.2.3408-1.2 | 8.2.3408-1.2 | Feb 27, 2017 | An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows. | |
| CVE-2017-5953 | Cri | 9.8 | < 8.2.3408-1.2 | 8.2.3408-1.2 | Feb 10, 2017 | vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow. | |
| CVE-2009-0316 | — | < 8.0.130-1.1 | 8.0.130-1.1 | Jan 28, 2009 | Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-59 | ||
| CVE-2007-2953 | — | < 8.2.3408-1.2 | 8.2.3408-1.2 | Jul 31, 2007 | Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command. | ||
| CVE-2007-2438 | — | < 8.2.3408-1.2 | 8.2.3408-1.2 | May 2, 2007 | The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines. |
- affected < 8.2.3408-1.2fixed 8.2.3408-1.2
An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.
- affected < 8.2.3408-1.2fixed 8.2.3408-1.2
vim before patch 8.0.0322 does not properly validate values for tree length when handling a spell file, which may result in an integer overflow at a memory allocation site and a resultant buffer overflow.
- CVE-2009-0316Jan 28, 2009affected < 8.0.130-1.1fixed 8.0.130-1.1
Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-59
- CVE-2007-2953Jul 31, 2007affected < 8.2.3408-1.2fixed 8.2.3408-1.2
Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.
- CVE-2007-2438May 2, 2007affected < 8.2.3408-1.2fixed 8.2.3408-1.2
The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write files via modelines.
Page 7 of 7