Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2023-70066
HistorySep 13, 2023 - 12:00 a.m.

Vim Input Validation Error Vulnerability

2023-09-1300:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
vim
input validation
vulnerability
remote code execution
http
https
integer overflow

0.001 Low

EPSS

Percentile

19.7%

Vim is a cross-platform text editor. An input validation error vulnerability exists in versions prior to Vim 9.0.1846 that stems from the presence of an integer overflow or wrap-around issue. A remote attacker can exploit this vulnerability by sending a malicious HTTP or HTTPS request to execute arbitrary shell commands with root user privileges.

CPENameOperatorVersion
vim vimlt9.0.1846