Lucene search

K
cveJpcertCVE-2010-3163
HistoryOct 25, 2010 - 8:01 p.m.

CVE-2010-3163

2010-10-2520:01:03
jpcert
web.nvd.nist.gov
27
cve-2010-3163
fenrir sleipnir
grani
untrusted search path vulnerability
privilege escalation
nvd

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

5.1%

Untrusted search path vulnerability in Fenrir Sleipnir before 2.9.5 and Grani before 4.4 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

Affected configurations

Nvd
Node
fenrirsleipnirRange2.9.4
OR
fenrirsleipnirMatch2.5.0
OR
fenrirsleipnirMatch2.5.1
OR
fenrirsleipnirMatch2.5.2
OR
fenrirsleipnirMatch2.5.3
OR
fenrirsleipnirMatch2.5.4
OR
fenrirsleipnirMatch2.5.5
OR
fenrirsleipnirMatch2.5.6
OR
fenrirsleipnirMatch2.5.7
OR
fenrirsleipnirMatch2.5.8
OR
fenrirsleipnirMatch2.5.9
OR
fenrirsleipnirMatch2.5.10
OR
fenrirsleipnirMatch2.5.11
OR
fenrirsleipnirMatch2.5.12
OR
fenrirsleipnirMatch2.5.13
OR
fenrirsleipnirMatch2.5.14
OR
fenrirsleipnirMatch2.5.15
OR
fenrirsleipnirMatch2.5.16
OR
fenrirsleipnirMatch2.5.17
OR
fenrirsleipnirMatch2.6.0
OR
fenrirsleipnirMatch2.6.1
OR
fenrirsleipnirMatch2.6.2
OR
fenrirsleipnirMatch2.7.0
OR
fenrirsleipnirMatch2.7.1
OR
fenrirsleipnirMatch2.7.1r2
OR
fenrirsleipnirMatch2.7.2
OR
fenrirsleipnirMatch2.8
OR
fenrirsleipnirMatch2.8.2
OR
fenrirsleipnirMatch2.8.3
OR
fenrirsleipnirMatch2.8.4
OR
fenrirsleipnirMatch2.8.5
OR
fenrirsleipnirMatch2.9
OR
fenrirsleipnirMatch2.9.1
OR
fenrirsleipnirMatch2.9.2
OR
fenrirsleipnirMatch2.9.3
Node
fenrirgraniRange4.3
OR
fenrirgraniMatch3.0
OR
fenrirgraniMatch3.1
OR
fenrirgraniMatch3.2
OR
fenrirgraniMatch3.5
OR
fenrirgraniMatch4.0
OR
fenrirgraniMatch4.1
OR
fenrirgraniMatch4.2
VendorProductVersionCPE
fenrirsleipnir*cpe:2.3:a:fenrir:sleipnir:*:*:*:*:*:*:*:*
fenrirsleipnir2.5.0cpe:2.3:a:fenrir:sleipnir:2.5.0:*:*:*:*:*:*:*
fenrirsleipnir2.5.1cpe:2.3:a:fenrir:sleipnir:2.5.1:*:*:*:*:*:*:*
fenrirsleipnir2.5.2cpe:2.3:a:fenrir:sleipnir:2.5.2:*:*:*:*:*:*:*
fenrirsleipnir2.5.3cpe:2.3:a:fenrir:sleipnir:2.5.3:*:*:*:*:*:*:*
fenrirsleipnir2.5.4cpe:2.3:a:fenrir:sleipnir:2.5.4:*:*:*:*:*:*:*
fenrirsleipnir2.5.5cpe:2.3:a:fenrir:sleipnir:2.5.5:*:*:*:*:*:*:*
fenrirsleipnir2.5.6cpe:2.3:a:fenrir:sleipnir:2.5.6:*:*:*:*:*:*:*
fenrirsleipnir2.5.7cpe:2.3:a:fenrir:sleipnir:2.5.7:*:*:*:*:*:*:*
fenrirsleipnir2.5.8cpe:2.3:a:fenrir:sleipnir:2.5.8:*:*:*:*:*:*:*
Rows per page:
1-10 of 431

CVSS2

6.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0

Percentile

5.1%

Related for CVE-2010-3163