Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2009-0316 Details

Description

Untrusted search path vulnerability in src/if_python.c in the Python interface in Vim before 7.2.045 allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983), as demonstrated by an erroneous search path for plugin/bike.vim in bicyclerepair.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=484305 CVE
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=493937 CVE
http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html CVE
https://bugzilla.redhat.com/show_bug.cgi?id=481565 CVE
https://exchange.xforce.ibmcloud.com/vulnerabilities/48275 CVE

see all 22 references

Weakness Enumeration

CWE-IDCWE NameSource
NVD-CWE-OtherWeakness Not in a Standard CWE Category[email protected]

Affected Products

ProductVersions
vim vim
<= 7.2
1.0
1.22
3.0
4.0

CPE

  • cpe:2.3:a:vim:vim:*:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:1.22:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:3.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:4.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:5.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:5.1:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:5.2:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:5.3:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:5.4:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:5.5:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:5.6:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:5.7:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:5.8:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:6.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:6.1:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:6.2:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:6.3:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:6.4:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:7.0:*:*:*:*:*:*:*
  • cpe:2.3:a:vim:vim:7.1:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2009-0316
NVD Published Date:
Jan 28, 2009
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2009-0316 Details - Not Deferred