VDB
CVE-2010-4142
CVE-2010-4142
PUBLISHED
CVSS 10 CRITICAL
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) SCPC_INITIALIZE, (2) SCPC_INITIALIZE_RF, or (3) SCPC_TXTEVENT packet. NOTE: it was later reported that 1.06 is also affected by one of these requests.
EPSS 49.08% · 97.8th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
49.08%
97.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| realflex | realwin | 1.06, 2.0 |
| n/a | n/a | n/a |
Timeline
- Oct 15, 2010 CVE Published
- Oct 15, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 2, 2023 EPSS Score
- Jun 22, 2023 EPSS Score
- Aug 11, 2023 EPSS Score
References
- 15259 exploit
- 44150 vdb
- http://aluigi.org/adv/realwin_1-adv.txt url
- 15337 exploit
- 41849 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2010-4142 advisory