Lucene search

K
cveMitreCVE-2010-1937
HistoryJun 15, 2010 - 2:30 p.m.

CVE-2010-1937

2010-06-1514:30:01
CWE-119
mitre
web.nvd.nist.gov
39
cve-2010-1937
buffer overflow
httpadapter
sblim sfcb
remote code execution
bug fix.

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.058

Percentile

93.5%

Heap-based buffer overflow in httpAdapter.c in httpAdapter in SBLIM SFCB before 1.3.8 might allow remote attackers to execute arbitrary code via a Content-Length HTTP header that specifies a value too small for the amount of POST data, aka bug #3001896.

Affected configurations

Nvd
Node
standards_based_linux_instrumentationsblim-sfcbRange1.3.7
OR
standards_based_linux_instrumentationsblim-sfcbMatch1.3.4
OR
standards_based_linux_instrumentationsblim-sfcbMatch1.3.5
OR
standards_based_linux_instrumentationsblim-sfcbMatch1.3.6
VendorProductVersionCPE
standards_based_linux_instrumentationsblim-sfcb*cpe:2.3:a:standards_based_linux_instrumentation:sblim-sfcb:*:*:*:*:*:*:*:*
standards_based_linux_instrumentationsblim-sfcb1.3.4cpe:2.3:a:standards_based_linux_instrumentation:sblim-sfcb:1.3.4:*:*:*:*:*:*:*
standards_based_linux_instrumentationsblim-sfcb1.3.5cpe:2.3:a:standards_based_linux_instrumentation:sblim-sfcb:1.3.5:*:*:*:*:*:*:*
standards_based_linux_instrumentationsblim-sfcb1.3.6cpe:2.3:a:standards_based_linux_instrumentation:sblim-sfcb:1.3.6:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

Low

EPSS

0.058

Percentile

93.5%