CVE-2010-1688
high · 9.3Stack-based buffer overflow in 2BrightSparks SyncBack Freeware 3.2.20.0, and possibly other versions before 3.2.21, allows user-assisted remote attackers to execute arbitrary code via a long filename in a (1) .sps or (2) zip profile.
9.3
CVSS
15.0%
EPSS (exploit prob.)
97th
EPSS percentile
2010-05-24
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| 2brightsparks | syncback | 3.2.20.0 |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/64752
- http://secunia.com/advisories/39865
- http://www.2brightsparks.com/freeware/changes.html
- http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-041-syncback-freeware-v3-2-20-0/
- http://www.corelan.be:8800/wp-content/forum-file-uploads/lincoln/syncbackup.rb_.txt
- http://www.securityfocus.com/bid/40311
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58727
- http://osvdb.org/64752
- http://secunia.com/advisories/39865
- http://www.2brightsparks.com/freeware/changes.html
- http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-041-syncback-freeware-v3-2-20-0/
- http://www.corelan.be:8800/wp-content/forum-file-uploads/lincoln/syncbackup.rb_.txt
- http://www.securityfocus.com/bid/40311
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58727
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-1688