CVE-2010-2361
Estado: ModificadaAlta (10)—
Winny 2.0b7.1 and earlier does not properly process BBS information, which has unspecified impact and remote attack vectors that might lead to use of the product's host for DDoS attacks.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.45%
- Percentil entre todas las CVEs puntuadas: 72
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://jvn.jp/en/jp/JVN54336184/index.html
- http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000027.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61278
- http://jvn.jp/en/jp/JVN54336184/index.html
- http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000027.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61278
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-2361",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-08-25T20:00:17.047",
"references": [
{
"url": "http://jvn.jp/en/jp/JVN54336184/index.html",
"source": "cve@mitre.org"
},
{
"url": "http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000027.html",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61278",
"source": "cve@mitre.org"
},
{
"url": "http://jvn.jp/en/jp/JVN54336184/index.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000027.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61278",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Winny 2.0b7.1 and earlier does not properly process BBS information, which has unspecified impact and remote attack vectors that might lead to use of the product's host for DDoS attacks."
},
{
"lang": "es",
"value": "Winny v2.0b7.1 y anteriores no maneja adecuadamente el proceso de información BBS, lo que tiene un impacto y vectores de ataque desconocidos que podrían emplear el host del producto para llevar a cabo ataques DDoS."
}
],
"lastModified": "2026-06-16T23:20:37.100",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:winny:winny:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F143B54-0121-4F08-A5B6-588A1A8F1DCB",
"versionEndIncluding": "2.0b7.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}