Vulnerabilities > CVE-2010-4435 - Unspecified vulnerability in SUN Sunos 5.10/5.8/5.9

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
sun
nessus
exploit available

Summary

Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to CDE Calendar Manager Service Daemon and RPC. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from other software vendors that this affects other operating systems, such as HP-UX, or claims from a reliable third party that this is a buffer overflow in rpc.cmsd via long XDR-encoded ASCII strings in RPC call 10.

Vulnerable Configurations

Part Description Count
OS
Sun
3

Exploit-Db

descriptionMultiple Vendor Calendar Manager Remote Code Execution. CVE-2010-4435. Remote exploits for multiple platform
fileexploits/multiple/remote/16137.c
idEDB-ID:16137
last seen2016-02-01
modified2011-02-09
platformmultiple
port
published2011-02-09
reporterRodrigo Rubira Branco
sourcehttps://www.exploit-db.com/download/16137/
titleMultiple Vendor Calendar Manager Remote Code Execution
typeremote

Nessus

  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHSS_41788.NASL
    descriptions700_800 11.31 CDE Applications Patch : A potential security vulnerability has been identified with HP-UX running CDE Calendar Manager. The vulnerability could be exploited remotely to execute arbitrary code. References: CVE-2010-4435, ZDI-CAN-561.
    last seen2020-06-01
    modified2020-06-02
    plugin id52040
    published2011-02-21
    reporterThis script is Copyright (C) 2011-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/52040
    titleHP-UX PHSS_41788 : HP-UX Running CDE Calendar Manager, Remote Execution of Arbitrary Code (HPSBUX02628 SSRT090183 rev.1)
  • NASL familyHP-UX Local Security Checks
    NASL idHPUX_PHSS_41174.NASL
    descriptions700_800 11.23 CDE Applications Patch : A potential security vulnerability has been identified with HP-UX running CDE Calendar Manager. The vulnerability could be exploited remotely to execute arbitrary code. References: CVE-2010-4435, ZDI-CAN-561.
    last seen2020-06-01
    modified2020-06-02
    plugin id52039
    published2011-02-21
    reporterThis script is Copyright (C) 2011-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/52039
    titleHP-UX PHSS_41174 : HP-UX Running CDE Calendar Manager, Remote Execution of Arbitrary Code (HPSBUX02628 SSRT090183 rev.1)

Oval

accepted2015-04-20T04:00:32.783-04:00
classvulnerability
contributors
  • nameYamini Mohan R
    organizationHewlett-Packard
  • nameSushant Kumar Singh
    organizationHewlett-Packard
  • namePrashant Kumar
    organizationHewlett-Packard
  • nameMike Cokus
    organizationThe MITRE Corporation
descriptionUnspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to CDE Calendar Manager Service Daemon and RPC. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from other software vendors that this affects other operating systems, such as HP-UX, or claims from a reliable third party that this is a buffer overflow in rpc.cmsd via long XDR-encoded ASCII strings in RPC call 10.
familyunix
idoval:org.mitre.oval:def:12794
statusaccepted
submitted2011-07-28T14:52:04.000-05:00
titleHP-UX Running CDE Calendar Manager, Remote Execution of Arbitrary Code
version48

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:70687
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-70687
titleMultiple Vendor Calendar Manager Remote Code Execution

References