CVE-2010-2632 describes an unspecified vulnerability in the FTP Server component of Oracle Solaris versions 8, 9, 10, and 11 Express, primarily impacting system availability. While Oracle initially provided limited details, reliable research suggests it involves a denial-of-service condition (CPU and memory exhaustion) triggered by remote authenticated users through crafted glob expressions in the libc glob implementation. With a CVSS score of 7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C), this vulnerability is considered high severity, indicating it can be exploited remotely with low attack complexity and without authentication, leading to a complete loss of availability. Its FAUCET Risk Score of 91/100 further emphasizes its significant potential impact. Despite its age, there is no evidence of active exploitation in the wild (not in KEV or Hot List). However, public exploit code exists (EDB-15215), demonstrating a proof-of-concept for resource exhaustion. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.8CPE matchmatch criteria | cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:* | ||
5.9CPE matchmatch criteria | cpe:2.3:o:sun:sunos:5.9:*:*:*:*:*:*:* | ||
5.10CPE matchmatch criteria | cpe:2.3:o:sun:sunos:5.10:*:*:*:*:*:*:* | ||
5.11CPE matchmatch criteria | cpe:2.3:o:sun:sunos:5.11:*:express:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.