Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-0411

27
FAUCET Score

CVE-2010-0411 describes multiple integer signedness errors in SystemTap versions 1.0 and 1.1, specifically within the __get_argv and __get_compat_argv functions. These flaws allow a local attacker to trigger a denial of service, potentially leading to a script crash, or even a system crash or hang, by supplying a process with an excessive number of arguments, which causes a buffer overflow. Rated with a CVSS score of 4.9 (AV:L/AC:L/Au:N/C:N/I:N/A:C), this vulnerability requires local access and low attack complexity to achieve a complete availability impact. While not listed in CISA's KEV catalog and lacking active exploitation, public exploit code exists (EDB-33604), though there is minimal community discussion or media coverage surrounding this decade-old issue.

Impacted Technologies

VendorProductVersion(s)CPE
1.1CPE matchmatch criteria
cpe:2.3:a:systemtap:systemtap:1.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.9MEDIUM

AV:L/AC:L/Au:N/C:N/I:N/A:C

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
6.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.95%
Probability of exploitation in next 30 days
EPSS Percentile
57.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-33604 · Feb 5, 2010
This CVE's current EPSS score of 0.0095 is in the 90th percentile among its peer group of 3,049 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: systemtap-0:0.6.2-2.el4_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: systemtap-0:0.9.7-5.el5_4.3
View patch

Vendor Advisories (1)

redhatCVE-2010-0411Moderate

systemtap: Crash with systemtap script using __get_argv()

Jan 29, 2010

References

lists.fedoraproject.org / pipermail/package-announce/2010-February/035201.html
lists.fedoraproject.org / pipermail/package-announce/2010-February/035261.html
lists.opensuse.org / opensuse-security-announce/2010-04/msg00006.html
marc.info
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/38426
Vendor Advisory
secunia.com / advisories/38680
secunia.com / advisories/38765
secunia.com / advisories/38817
secunia.com / advisories/39656
securitytracker.com / id
sourceware.org / bugzilla/show_bug.cgi
sourceware.org / git/gitweb.cgi
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9675
redhat.com / support/errata/RHSA-2010-0124.html
redhat.com / support/errata/RHSA-2010-0125.html
securityfocus.com / bid/38120
Exploit
vupen.com / english/advisories/2010/1001