← Back

CVE-2010-3914

nvd nist
Published: Nov 3, 2010Modified: Apr 29, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.

Affected (33)

Products: Vim: Gvim
1 product
Gvim
Configuration A
33 vulnerable
Vulnerable SoftwareAffected Versions
Vim
Up to 7.3.033
Version 7.3.010
Version 7.3.011
Version 7.3.012
Version 7.3.013
Version 7.3.014
Version 7.3.015
Version 7.3.016
Version 7.3.017
Version 7.3.018
Version 7.3.019
Version 7.3.01
Version 7.3.020
Version 7.3.021
Version 7.3.022
Version 7.3.023
Version 7.3.024
Version 7.3.025
Version 7.3.026
Version 7.3.027
Version 7.3.028
Version 7.3.029
Version 7.3.02
Version 7.3.030
Version 7.3.031
Version 7.3.032
Version 7.3.03
Version 7.3.04
Version 7.3.05
Version 7.3.06
Version 7.3.07
Version 7.3.08
Version 7.3.09

References (10)

ftp://ftp.vim.org/pub/vim/patches/7.3/7.3.034 (unsafe URL)
Source: vultures@jpcert.or.jp
Patch
Source: vultures@jpcert.or.jp
Patch
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: vultures@jpcert.or.jp
ftp://ftp.vim.org/pub/vim/patches/7.3/7.3.034 (unsafe URL)
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.