Vim is a widely used text editor and command-line tool embedded across development environments, system administration workflows, and Unix-like systems, giving its vulnerability footprint disproportionate reach despite a narrow product scope. The vendor's disclosures recur around OS command injection and related input-handling issues in the editor's scripting and filter mechanisms, while public exploit code has frequently accompanied disclosed vulnerabilities. Defenders should treat Vim updates as broadly applicable across their infrastructure; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vim Development Group over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2368HIGH vim 6.3 before 6.3.082, with modelines enabled, allows external user-assisted attackers to execute arbitrary commands via shell metacharacters in the (1) glob or (2) expand command | Jul 26, 2005 | 9.3 | 24 | NO | NO |
vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writ | Jun 18, 2001 | 2.1 | 21 | NO | YES |
CVE-2007-2438HIGH The sandbox for vim allows dangerous functions such as (1) writefile, (2) feedkeys, and (3) system, which might allow user-assisted attackers to execute shell commands and write fi | May 2, 2007 | 7.6 | 20 | NO | NO |
CVE-2007-2953MEDIUM Format string vulnerability in the helptags_one function in src/ex_cmds.c in Vim 6.4 and earlier, and 7.x up to 7.1, allows user-assisted remote attackers to execute arbitrary code | Jul 31, 2007 | 6.8 | 19 | NO | NO |
CVE-2004-1138HIGH VIM before 6.3 and gVim before 6.3 allow local users to execute arbitrary commands via a file containing a crafted modeline that is executed when the file is viewed using options s | Jan 10, 2005 | 7.2 | 18 | NO | NO |
CVE-2002-1377MEDIUM vim 6.0 and 6.1, and possibly other versions, allows attackers to execute arbitrary commands using the libcall feature in modelines, which are not sandboxed but may be executed whe | Dec 23, 2002 | 4.6 | 17 | NO | NO |
CVE-2001-0408MEDIUM vim (aka gvim) processes VIM control codes that are embedded in a file, which could allow attackers to execute arbitrary commands when another user opens a file containing maliciou | Jun 18, 2001 | 5.1 | 15 | NO | NO |
CVE-2005-0069MEDIUM The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files. | Jan 13, 2005 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vim Development Group.
Media articles that mention a CVE ID that affects a product developed by Vim Development Group — matched by CVE ID, not by vendor name.