Lucene search

K
osvGoogleOSV:USN-5247-1
HistoryJan 27, 2022 - 6:37 a.m.

vim vulnerabilities

2022-01-2706:37:23
Google
osv.dev
10

7.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

42.1%

It was discovered that vim incorrectly handled parsing of filenames in its
search functionality. If a user was tricked into opening a specially crafted
file, an attacker could crash the application, leading to a denial of
service. This issue only affected Ubuntu 21.10. (CVE-2021-3973)

It was discovered that vim incorrectly handled memory when opening and
searching the contents of certain files. If a user was tricked into opening
a specially crafted file, an attacker could crash the application, leading to
a denial of service, or possibly achieve code execution with user privileges.
This issue only affected Ubuntu 20.04 LTS and Ubuntu 21.10. (CVE-2021-3974)

It was discovered that vim incorrectly handled memory when opening and editing
certain files. If a user was tricked into opening a specially crafted file, an
attacker could crash the application, leading to a denial of service, or
possibly achieve code execution with user privileges. (CVE-2021-3984)

It was discovered that vim incorrectly handled memory when opening and editing
certain files. If a user was tricked into opening a specially crafted file, an
attacker could crash the application, leading to a denial of service, or
possibly achieve code execution with user privileges. (CVE-2021-4019)

It was discovered that vim incorrectly handled memory when opening and editing
certain files. If a user was tricked into opening a specially crafted file, an
attacker could crash the application, leading to a denial of service, or
possibly achieve code execution with user privileges.(CVE-2021-4069)