← back
CVE-2010-1039

CVE-2010-1039

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 20%
from disclosure to weapon59 days
Published on NVDMay 20
1st PoC+59d
exploitation probability
20%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.