CVE-2010-1318
Multiple Vendor AgentX++ - Stack Buffer Overflow (PoC)
Severity Score
10.0
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vectors.
Un desbordamiento de búfer en la región stack de la memoria en la función AgentX::receive_agentx en AgentX++ versión 1.4.16, tal y como es usado en RealNetworks Helix Server y Helix Mobile Server versión 11.x hasta 13.x y otros productos, permite a los atacantes remotos ejecutar código arbitrario por medio de vectores no especificados.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2010-04-08 CVE Reserved
- 2010-04-17 CVE Published
- 2010-04-17 First Exploit
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.realnetworks.com/uploadedFiles/Support/helix-support/SecurityUpdate041410HS.pdf | X_refsource_confirm | |
http://www.securityfocus.com/bid/39490 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/12274 | 2010-04-17 | |
https://www.exploit-db.com/exploits/16452 | 2010-05-11 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/39279 | 2010-11-24 | |
http://www.vupen.com/english/advisories/2010/0889 | 2010-11-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Realnetworks Search vendor "Realnetworks" | Helix Mobile Server Search vendor "Realnetworks" for product "Helix Mobile Server" | <= 13.1.1 Search vendor "Realnetworks" for product "Helix Mobile Server" and version " <= 13.1.1" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Helix Server Search vendor "Realnetworks" for product "Helix Server" | <= 13.1.1 Search vendor "Realnetworks" for product "Helix Server" and version " <= 13.1.1" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Helix Server Search vendor "Realnetworks" for product "Helix Server" | 11.0 Search vendor "Realnetworks" for product "Helix Server" and version "11.0" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Helix Server Search vendor "Realnetworks" for product "Helix Server" | 11.1 Search vendor "Realnetworks" for product "Helix Server" and version "11.1" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Helix Server Search vendor "Realnetworks" for product "Helix Server" | 12.0.0 Search vendor "Realnetworks" for product "Helix Server" and version "12.0.0" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Helix Server Search vendor "Realnetworks" for product "Helix Server" | 12.0.1 Search vendor "Realnetworks" for product "Helix Server" and version "12.0.1" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Helix Server Mobile Search vendor "Realnetworks" for product "Helix Server Mobile" | 11.0 Search vendor "Realnetworks" for product "Helix Server Mobile" and version "11.0" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Helix Server Mobile Search vendor "Realnetworks" for product "Helix Server Mobile" | 12.0.0 Search vendor "Realnetworks" for product "Helix Server Mobile" and version "12.0.0" | - |
Affected
| ||||||
Realnetworks Search vendor "Realnetworks" | Helix Server Mobile Search vendor "Realnetworks" for product "Helix Server Mobile" | 13.0.0 Search vendor "Realnetworks" for product "Helix Server Mobile" and version "13.0.0" | - |
Affected
|