4.3

CVE-2008-4677

autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords.  NOTE: the upstream vendor disputes a vector involving different ports on the same host, stating "I'm assuming that they're using the same id and password on that unchanged hostname, deliberately."

Data is provided by the National Vulnerability Database (NVD)
VimNetrw Version109
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version110
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version111
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version112
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version113
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version114
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version115
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version116
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version118
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version120
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version121
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version122
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version123
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version128
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
VimNetrw Version131
   VimVim Version7.1
   VimVim Version7.1.266
   VimVim Version7.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.93% 0.739
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N