Vim 8.0 allows attackers to cause a denial of service (invalid free) or possibly have unspecified other impact via a crafted source (aka -S) file. NOTE: there might be a limited number of scenarios in which this has security relevance.
[ { "events": [ { "introduced": "0" }, { "last_affected": "8.0" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-11109.json"