Vulnerabilities > VIM > VIM > 8.0.1779

DATE CVE VULNERABILITY TITLE RISK
2021-09-06 CVE-2021-3770 vim is vulnerable to Heap-based Buffer Overflow
local
low complexity
vim fedoraproject netapp
7.8
2020-05-28 CVE-2019-20807 OS Command Injection vulnerability in multiple products
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
5.3
2019-06-05 CVE-2019-12735 OS Command Injection vulnerability in multiple products
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via the :source! command in a modeline, as demonstrated by execute in Vim, and assert_fails or nvim_input in Neovim.
local
low complexity
vim neovim CWE-78
8.6