CVE-2015-10067 is a high-severity race condition vulnerability (CWE-362, CWE-366) affecting the SSharpSmartThreadPool component within the oznetmaster SSharpSmartThreadPool project. This flaw, located in an unspecified part of SSharpSmartThreadPool/SmartThreadPool.cs, could allow an attacker to manipulate thread execution. The vulnerability has a CVSS v3.1 score of 8.1 (High), indicating a high potential for impact on confidentiality, integrity, and availability if exploited. However, exploitation is considered difficult due to high attack complexity, and the attack vector is network-based. There is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting low public awareness. A patch (0e58073c831093aad75e077962e9fb55cad0dc5f) is available to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2015-03-13CPE matchmatch criteria | cpe:2.3:a:ssharpsmartthreadpool_project:ssharpsmartthreadpool:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.