Vulnerabilities > VIM Development Group > VIM > 6.3.044

DATE CVE VULNERABILITY TITLE RISK
2005-07-26 CVE-2005-2368 OS Command Injection vulnerability in VIM Development Group VIM
vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand commands of a foldexpr expression for calculating fold levels.
network
vim-development-group CWE-78
critical
9.3
2005-01-13 CVE-2005-0069 Unspecified vulnerability in VIM Development Group VIM
The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files.
local
low complexity
vim-development-group
4.6
2005-01-10 CVE-2004-1138 Unspecified vulnerability in VIM Development Group VIM
VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options such as (1) termcap, (2) printdevice, (3) titleold, (4) filetype, (5) syntax, (6) backupext, (7) keymap, (8) patchmode, or (9) langmenu.
local
low complexity
vim-development-group
7.2