← All CVEs

CVE-2010-1039

high · 10

Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.31_09 and earlier on HP HP-UX B.11.11, B.11.23, and B.11.31; and SGI IRIX 6.5 allows remote attackers to execute arbitrary code via an RPC request containing format string specifiers in an invalid directory name.

10
CVSS
20.2%
EPSS (exploit prob.)
97th
EPSS percentile
2010-05-20
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-134

Affected products

VendorProductAffected versions
hpnfs/oncplus<= b.11.31_09
hphp-uxb.11.11
hphp-uxb.11.23
hphp-uxb.11.31
ibmaix<= 5.3
ibmaix1.2.1
ibmaix1.3
ibmaix2.2.1
ibmaix3.1
ibmaix3.2
ibmaix3.2.0
ibmaix3.2.4
ibmaix3.2.5
ibmaix4
ibmaix4.0
ibmaix4.1
ibmaix4.1.1
ibmaix4.1.2
ibmaix4.1.3
ibmaix4.1.4
ibmaix4.1.5
ibmaix4.2
ibmaix4.2.0
ibmaix4.2.1
ibmaix4.2.1.12
ibmaix4.3
ibmaix4.3.0
ibmaix4.3.1
ibmaix4.3.2
ibmaix4.3.3
ibmaix5.1
ibmaix5.1.0.10
ibmaix5.1l
ibmaix5.2
ibmaix5.2.0
ibmaix5.2.0.50
ibmaix5.2.0.54
ibmaix5.2.2
ibmaix5.2_l
ibmaix6.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-1039