← back
CVE-2010-4435

CVE-2010-4435

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 14%
from disclosure to weapon21 days
Published on NVDJan 19
1st PoC+21d
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to CDE Calendar Manager Service Daemon and RPC. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from other software vendors that this affects other operating systems, such as HP-UX, or claims from a reliable third party that this is a buffer overflow in rpc.cmsd via long XDR-encoded ASCII strings in RPC call 10.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.