CVE-2010-1685 describes a stack-based buffer overflow vulnerability in CursorArts ZipWrangler 1.20. This flaw allows user-assisted remote attackers to execute arbitrary code by enticing a victim to open a specially crafted ZIP file containing an excessively long filename. With a CVSS score of 9.3, this vulnerability is critical, as it can lead to complete compromise of confidentiality, integrity, and availability with moderate attack complexity. While not actively exploited in the wild (no KEV or Hot List status), public exploit code exists on ExploitDB, indicating its potential for exploitation, though it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.20CPE matchmatch criteria | cpe:2.3:a:cursorarts:zipwrangler:1.20:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.