CVE-2010-3277
Summary
| CVE | CVE-2010-3277 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2010-09-28 18:00:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Player | 3.0 | All | All | All |
| Application | Vmware | Player | 3.0.1 | All | All | All |
| Application | Vmware | Player | 3.1 | All | All | All |
| Application | Vmware | Player | 3.1.1 | All | All | All |
| Application | Vmware | Workstation | 7.0 | All | All | All |
| Application | Vmware | Workstation | 7.0.1 | All | All | All |
| Application | Vmware | Workstation | 7.1 | All | All | All |
| Application | Vmware | Workstation | 7.1.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [Security-announce] VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues | af854a3a-2127-422b-91ae-364da2661108 | lists.vmware.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| VMSA-2010-0014 | af854a3a-2127-422b-91ae-364da2661108 | www.vmware.com | Vendor Advisory |
| SecurityTracker.com Archives - VMware Workstation and Player Installer Displays HTML File From Current Working Directory | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| VMware Update for Workstation and Player - Advisories - Community | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.