Lucene search

K
cveFlexeraCVE-2007-2953
HistoryJul 31, 2007 - 10:17 a.m.

CVE-2007-2953

2007-07-3110:17:00
flexera
web.nvd.nist.gov
38
cve-2007-2953
vulnerability
vim
format string
helptags command
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.331

Percentile

97.1%

Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code via format string specifiers in a help-tags tag in a help file, related to the helptags command.

Affected configurations

Nvd
Node
vim_development_groupvimRange≀6.4
OR
vim_development_groupvimMatch7.0
OR
vim_development_groupvimMatch7.1
OR
vim_development_groupvimMatch7.1.38
VendorProductVersionCPE
vim_development_groupvim7.0cpe:/a:vim_development_group:vim:7.0:::
vim_development_groupvim7.1.38cpe:/a:vim_development_group:vim:7.1.38:::
vim_development_groupvimcpe:/a:vim_development_group:vim::::
vim_development_groupvim7.1cpe:/a:vim_development_group:vim:7.1:::

References

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.331

Percentile

97.1%