Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-4409

38
FAUCET Score

CVE-2010-4409 describes an integer overflow vulnerability in the NumberFormatter::getSymbol function within PHP versions 5.3.3 and earlier. This flaw allows an unauthenticated attacker to trigger a denial of service (application crash) by providing an invalid argument. While the CVSS score is moderate at 5.0, its FAUCET Risk Score is high at 96/100, indicating a significant potential impact despite the low EPSS score. An exploit for this vulnerability is publicly available on ExploitDB, but there is no evidence of active exploitation, Metasploit or Nuclei modules, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 5.3.3CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
1.0CPE matchmatch criteria
cpe:2.3:a:php:php:1.0:*:*:*:*:*:*:*
2.0CPE matchmatch criteria
cpe:2.3:a:php:php:2.0:*:*:*:*:*:*:*
2.0b10CPE matchmatch criteria
cpe:2.3:a:php:php:2.0b10:*:*:*:*:*:*:*
3.0CPE matchmatch criteria
cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
18.88%
Probability of exploitation in next 30 days
EPSS Percentile
97.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-15722 · Dec 10, 2010
This CVE's current EPSS score of 0.1888 is in the 97th percentile among its peer group of 23,723 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2010-4409Low

php: getSymbol() integer overflow vulnerability

Nov 19, 2010

References

lists.apple.com / archives/security-announce/2011/Mar/msg00006.html
lists.fedoraproject.org / pipermail/package-announce/2011-January/052836.html
lists.fedoraproject.org / pipermail/package-announce/2011-January/052845.html
lists.opensuse.org / opensuse-updates/2012-01/msg00035.html
secunia.com / advisories/42812
secunia.com / advisories/47674
support.apple.com / kb/HT4581
svn.php.net / viewvc/php/php-src/trunk/ext/intl/formatter/formatter_attr.c
Patch
svn.php.net / viewvc
Patch
exploit-db.com / exploits/15722
kb.cert.org / vuls/id/479900
US Government Resource
mandriva.com / security/advisories
mandriva.com / security/advisories
php.net / ChangeLog-5.php
securityfocus.com / archive/1/515142/100/0/threaded
securityfocus.com / bid/45119
ubuntu.com / usn/USN-1042-1
vupen.com / english/advisories/2011/0020
vupen.com / english/advisories/2011/0021
vupen.com / english/advisories/2011/0077