CVE-2008-2712 describes a critical vulnerability in Vim versions 7.1.314, 6.4, and others, allowing user-assisted remote attackers to execute arbitrary commands. This occurs because Vim scripts, such as filetype.vim and xpm.vim, fail to properly sanitize inputs before invoking the execute or system functions. With a CVSS score of 9.3, this vulnerability is highly severe, indicating a network-based attack with medium complexity that can lead to complete compromise of confidentiality, integrity, and availability. While not listed in KEV, exploit code is available on ExploitDB, though there is minimal community discussion or media coverage surrounding this older vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.4CPE matchmatch criteria | cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* | ||
>= 7.0, <= 7.1.314CPE matchmatch criteria | cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:* | ||
6.06CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:lts:*:*:* | ||
7.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:7.10:*:*:*:*:*:*:* | ||
8.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.