CVE-2010-4435 is an unspecified vulnerability in the CDE Calendar Manager Service Daemon (rpc.cmsd) affecting Oracle Solaris 8, 9, and 10. This critical vulnerability has a CVSS score of 10.0, indicating it can be exploited remotely without authentication to compromise confidentiality, integrity, and availability. While Oracle has not confirmed, third-party claims suggest it's a buffer overflow via long XDR-encoded ASCII strings. Despite its age and high severity, there is no evidence of active exploitation, though exploit code for remote code execution is publicly available on ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.8CPE matchmatch criteria | cpe:2.3:o:sun:sunos:5.8:*:*:*:*:*:*:* | ||
5.9CPE matchmatch criteria | cpe:2.3:o:sun:sunos:5.9:*:*:*:*:*:*:* | ||
5.10CPE matchmatch criteria | cpe:2.3:o:sun:sunos:5.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.