Логотип exploitDog
bind:CVE-2018-11319
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-11319

Количество 4

Количество 4

ubuntu логотип

CVE-2018-11319

больше 7 лет назад

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-11319

больше 7 лет назад

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-11319

больше 7 лет назад

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle s ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-x97c-px3m-v4g2

больше 3 лет назад

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2018-11319

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed.

CVSS3: 7.5
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-11319

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed.

CVSS3: 7.5
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-11319

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle s ...

CVSS3: 7.5
1%
Низкий
больше 7 лет назад
github логотип
GHSA-x97c-px3m-v4g2

Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу