{"api_version":"1","generated_at":"2026-07-23T07:17:28+00:00","cve":"CVE-2010-3277","urls":{"html":"https://cve.report/CVE-2010-3277","api":"https://cve.report/api/cve/CVE-2010-3277.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-3277","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-3277"},"summary":{"title":"CVE-2010-3277","description":"The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-09-28 18:00:03","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://lists.vmware.com/pipermail/security-announce/2010/000105.html","name":"http://lists.vmware.com/pipermail/security-announce/2010/000105.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Security-announce] VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2010/2491","name":"http://www.vupen.com/english/advisories/2010/2491","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vmware.com/security/advisories/VMSA-2010-0014.html","name":"http://www.vmware.com/security/advisories/VMSA-2010-0014.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"VMSA-2010-0014","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1024481","name":"http://securitytracker.com/id?1024481","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - VMware Workstation and Player Installer Displays HTML File From Current Working Directory","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/41574","name":"http://secunia.com/advisories/41574","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"VMware Update for Workstation and Player - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-3277","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-3277","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"3277","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"player","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3277","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"player","cpe6":"3.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3277","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"player","cpe6":"3.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3277","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"player","cpe6":"3.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3277","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"workstation","cpe6":"7.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3277","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"workstation","cpe6":"7.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3277","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"workstation","cpe6":"7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"3277","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"vmware","cpe5":"workstation","cpe6":"7.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T03:03:18.872Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.vmware.com/security/advisories/VMSA-2010-0014.html"},{"name":"41574","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/41574"},{"name":"[security-announce] 20100923 VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://lists.vmware.com/pipermail/security-announce/2010/000105.html"},{"name":"ADV-2010-2491","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2010/2491"},{"name":"1024481","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1024481"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-09-28T17:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.vmware.com/security/advisories/VMSA-2010-0014.html"},{"name":"41574","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/41574"},{"name":"[security-announce] 20100923 VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues","tags":["mailing-list","x_refsource_MLIST"],"url":"http://lists.vmware.com/pipermail/security-announce/2010/000105.html"},{"name":"ADV-2010-2491","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2010/2491"},{"name":"1024481","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1024481"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-3277","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.vmware.com/security/advisories/VMSA-2010-0014.html","refsource":"CONFIRM","url":"http://www.vmware.com/security/advisories/VMSA-2010-0014.html"},{"name":"41574","refsource":"SECUNIA","url":"http://secunia.com/advisories/41574"},{"name":"[security-announce] 20100923 VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues","refsource":"MLIST","url":"http://lists.vmware.com/pipermail/security-announce/2010/000105.html"},{"name":"ADV-2010-2491","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2010/2491"},{"name":"1024481","refsource":"SECTRACK","url":"http://securitytracker.com/id?1024481"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-3277","datePublished":"2010-09-28T17:00:00.000Z","dateReserved":"2010-09-09T00:00:00.000Z","dateUpdated":"2024-09-17T03:49:11.046Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-09-28 18:00:03","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:workstation:7.0:*:*:*:*:*:*:*","matchCriteriaId":"AB33DBC9-3B63-457E-A353-B9E7378211AE"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:workstation:7.0.1:*:*:*:*:*:*:*","matchCriteriaId":"34F436D4-B7B7-43CB-A2BD-C5E791F7E3C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:workstation:7.1:*:*:*:*:*:*:*","matchCriteriaId":"BF53DB66-4C79-47BB-AABD-6DCE2EF98E1E"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:workstation:7.1.1:*:*:*:*:*:*:*","matchCriteriaId":"13A31E93-7671-492E-A78F-89CF4703B04D"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:player:3.0:*:*:*:*:*:*:*","matchCriteriaId":"5F747AC1-E163-41A4-BAC7-FDF46F4057D5"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:player:3.0.1:*:*:*:*:*:*:*","matchCriteriaId":"5A115959-9CDA-45ED-9002-BA1A31074E81"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:player:3.1:*:*:*:*:*:*:*","matchCriteriaId":"C158CD97-41BA-4422-9A55-B1A8650A0900"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:player:3.1.1:*:*:*:*:*:*:*","matchCriteriaId":"477D5F22-7DDD-461D-9CD1-2B2A968F6CB7"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"3277","Ordinal":"1","Title":"CVE-2010-3277","CVE":"CVE-2010-3277","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"3277","Ordinal":"1","NoteData":"The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file.","Type":"Description","Title":"CVE-2010-3277"},{"CveYear":"2010","CveId":"3277","Ordinal":"2","NoteData":"2010-09-28","Type":"Other","Title":"Published"}]}}}