Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2017-5953

25
FAUCET Score

CVE-2017-5953 describes an integer overflow vulnerability in Vim versions prior to 8.0.0322, specifically when processing spell files. This flaw can lead to a buffer overflow during memory allocation. With a CVSS score of 9.8 (Critical), this vulnerability allows for remote, low-complexity attacks that could result in complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is no public exploit code available, no evidence of active exploitation, and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 8.0.0055CPE matchmatch criteria
cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
2.83%
Probability of exploitation in next 30 days
EPSS Percentile
85.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0283 is in the 76th percentile among its peer group of 36,897 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

github_advisorypatch availablevia nvd_reference
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: vim
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: vim
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: vim

Vendor Advisories (1)

redhatCVE-2017-5953Low

vim: Tree length values not validated properly when handling a spell file

Feb 8, 2017

References

github.com / vim/vim/commit/399c297aa93afe2c0a39e2a1b3f972aebba44c9d
PatchVendor Advisory
groups.google.com / forum
security.gentoo.org / glsa/201706-26
usn.ubuntu.com / 4016-1
usn.ubuntu.com / 4309-1
debian.org / security/2017/dsa-3786
securityfocus.com / bid/96217