Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-4756

18
FAUCET Score

CVE-2010-4756 describes a denial-of-service vulnerability in the GNU C Library (glibc) glob implementation, affecting systems using glibc. Authenticated remote attackers can exploit this by submitting crafted glob expressions that do not match any pathnames, leading to high CPU and memory consumption. With a CVSS score of 4.0 (AV:N/AC:L/Au:S/C:N/I:N/A:P), it is considered a low-severity issue, requiring authentication and causing only availability impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.0MEDIUM

AV:N/AC:L/Au:S/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
SINGLE
Exploitability Score
8.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.63%
Probability of exploitation in next 30 days
EPSS Percentile
84.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0263 is in the 94th percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (7)

microsoftpatch availablevia msrc
Product: cm1 glibc 2.28-24 on CBL Mariner 1.0Fixed in: 2.28-24
microsoftpatch availablevia msrc
Product: cbl2 glibc 2.35-7 on CBL Mariner 2.0Fixed in: 2.35-7
microsoftpatch availablevia msrc
Product: 17077-16820Fixed in: 2.28-24
microsoftpatch availablevia msrc
Product: 17348-16823Fixed in: 2.35-7
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: glibc
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: glibc
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: glibc

Vendor Advisories (2)

microsoft2011-Mar/CVE-2010-4756Moderate

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

Mar 2, 2011
redhatCVE-2010-4756Low

glibc: glob implementation can cause excessive CPU and memory consumption due to crafted glob expressions

Oct 7, 2010

References

security.netapp.com / advisory/ntap-20241108-0002
cxib.net / stuff/glob-0day.c
Exploit
bugzilla.redhat.com / show_bug.cgi
bugzilla.redhat.com / show_bug.cgi
securityreason.com / achievement_securityalert/89
Exploit
securityreason.com / exploitalert/9223
Exploit