PoC Index

CVE-2010-4435

HIGH 10.0EPSS 14.2%

Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to CDE Calendar Manager Service Daemon and RPC. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from other software vendors that this affects other operating systems, such as HP-UX, or claims from a reliable third party that this is a buffer overflow in rpc.cmsd via long XDR-encoded ASCII strings in RPC call 10.

CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
14.17% chance of exploitation in the next 30 days, 96th percentile
Published
2011-01-19
Updated
2024-08-07

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related