Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-2448

Опубликовано: 12 июл. 2010
Источник: nvd
CVSS2: 3.5
EPSS Низкий

Описание

znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.

Комментарий

Per: http://cwe.mitre.org/data/definitions/476.html

'CWE-476: NULL Pointer Dereference'

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:znc:znc:*:*:*:*:*:*:*:*
Версия до 0.090 (включая)
cpe:2.3:a:znc:znc:0.034:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.041:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.043:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.044:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.045:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.047:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.050:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.052:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.054:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.056:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.058:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.060:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.062:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.064:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.066:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.068:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.070:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.072:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.074:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.076:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.078:*:*:*:*:*:*:*
cpe:2.3:a:znc:znc:0.080:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01247
Низкий

3.5 Low

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 15 лет назад

znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.

debian
больше 15 лет назад

znc.cpp in ZNC before 0.092 allows remote authenticated users to cause ...

github
больше 3 лет назад

znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.

EPSS

Процентиль: 79%
0.01247
Низкий

3.5 Low

CVSS2

Дефекты

NVD-CWE-Other