VDB
CVE-2010-1677
CVE-2010-1677
PUBLISHED
CVSS 5 MEDIUM
MHonArc 2.6.16 allows remote attackers to cause a denial of service (CPU consumption) via start tags that are placed within other start tags, as demonstrated by a <bo<bo<bo<bo<body>dy>dy>dy>dy> sequence, a different vulnerability than CVE-2010-4524.
EPSS 11.14% · 93.6th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
11.14%
93.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mhonarc | mhonarc | 2.6.16 |
| n/a | n/a | n/a |
Timeline
- Jan 3, 2011 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 18, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- mhonarc-start-tags-dos(64656) vdb
- ADV-2010-3344 vdb
- [mhonarc-dev] 20101230 [bug #32014] CVE-2010-1677: DoS when processing html messages with deep tag nesting mailing-list
- ADV-2011-0067 vdb
- 42694 third-party-advisory
- http://savannah.nongnu.org/bugs/?32014 url
- MDVSA-2011:003 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-1677 advisory
- http://www.mail-archive.com/mhonarc-dev@mhonarc.org/msg01297.html url