Lucene search

K
cve[email protected]CVE-2010-3277
HistoryOct 03, 2022 - 4:20 p.m.

CVE-2010-3277

2022-10-0316:20:57
CWE-264
web.nvd.nist.gov
27
vmware
workstation
player
installer
vulnerability
cve-2010-3277
nvd
web script
html

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

8.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

The installer in VMware Workstation 7.x before 7.1.2 build 301548 and VMware Player 3.x before 3.1.2 build 301548 renders an index.htm file if present in the installation directory, which might allow local users to trigger unintended interpretation of web script or HTML by creating this file.

Affected configurations

NVD
Node
vmwareworkstationMatch7.0
OR
vmwareworkstationMatch7.0.1
OR
vmwareworkstationMatch7.1
OR
vmwareworkstationMatch7.1.1
Node
vmwareplayerMatch3.0
OR
vmwareplayerMatch3.0.1
OR
vmwareplayerMatch3.1
OR
vmwareplayerMatch3.1.1

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

8.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%