9.3

CVE-2010-3914

Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file.  NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Vim ≫ Gvim Version <= 7.3.033
Vim ≫ Gvim Version 7.3.01
Vim ≫ Gvim Version 7.3.02
Vim ≫ Gvim Version 7.3.03
Vim ≫ Gvim Version 7.3.04
Vim ≫ Gvim Version 7.3.05
Vim ≫ Gvim Version 7.3.06
Vim ≫ Gvim Version 7.3.07
Vim ≫ Gvim Version 7.3.08
Vim ≫ Gvim Version 7.3.09
Vim ≫ Gvim Version 7.3.010
Vim ≫ Gvim Version 7.3.011
Vim ≫ Gvim Version 7.3.012
Vim ≫ Gvim Version 7.3.013
Vim ≫ Gvim Version 7.3.014
Vim ≫ Gvim Version 7.3.015
Vim ≫ Gvim Version 7.3.016
Vim ≫ Gvim Version 7.3.017
Vim ≫ Gvim Version 7.3.018
Vim ≫ Gvim Version 7.3.019
Vim ≫ Gvim Version 7.3.020
Vim ≫ Gvim Version 7.3.021
Vim ≫ Gvim Version 7.3.022
Vim ≫ Gvim Version 7.3.023
Vim ≫ Gvim Version 7.3.024
Vim ≫ Gvim Version 7.3.025
Vim ≫ Gvim Version 7.3.026
Vim ≫ Gvim Version 7.3.027
Vim ≫ Gvim Version 7.3.028
Vim ≫ Gvim Version 7.3.029
Vim ≫ Gvim Version 7.3.030
Vim ≫ Gvim Version 7.3.031
Vim ≫ Gvim Version 7.3.032
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.26% 0.947
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
ftp://ftp.vim.org/pub/vim/patches/7.3/7.3.034
Patch
http://jvn.jp/en/jp/JVN27868039/index.html
Patch
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000051.html
http://secunia.com/advisories/42084
Vendor Advisory
http://www.securityfocus.com/bid/44588