Vulnerabilities > VIM

DATE CVE VULNERABILITY TITLE RISK
2008-10-22 CVE-2008-4677 Credentials Management vulnerability in VIM Netrw
autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords.
network
vim CWE-255
4.3
2008-09-18 CVE-2008-4101 Improper Input Validation vulnerability in VIM
Vim 3.0 through 7.x before 7.2.010 does not properly escape characters, which allows user-assisted attackers to (1) execute arbitrary shell commands by entering a K keystroke on a line that contains a ";" (semicolon) followed by a command, or execute arbitrary Ex commands by entering an argument after a (2) "Ctrl-]" (control close-square-bracket) or (3) "g]" (g close-square-bracket) keystroke sequence, a different issue than CVE-2008-2712.
network
vim CWE-20
critical
9.3
2008-07-24 CVE-2008-3294 Code Injection vulnerability in VIM
src/configure.in in Vim 5.0 through 7.1, when used for a build with Python support, does not ensure that the Makefile-conf temporary file has the intended ownership and permissions, which allows local users to execute arbitrary code by modifying this file during a time window, or by creating it ahead of time with permissions that prevent its modification by configure.
local
high complexity
vim CWE-94
3.7
2008-06-16 CVE-2008-2712 Improper Input Validation vulnerability in VIM
Vim 7.1.314, 6.4, and other versions allows user-assisted remote attackers to execute arbitrary commands via Vim scripts that do not properly sanitize inputs before invoking the execute or system functions, as demonstrated using (1) filetype.vim, (3) xpm.vim, (4) gzip_vim, and (5) netrw.
network
vim canonical CWE-20
critical
9.3