« Volver al listado

CVE-2010-0359

Estado: ModificadaAlta (10)—

Buffer overflow in the SSLv2 support in Zeus Web Server before 4.3r5 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in an invalid Client Hello message.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2010-0359",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-01-20T16:30:00.523",
  "references": [
    {
      "url": "http://intevydis.blogspot.com/2010/01/zeus-web-server-ssl2clienthello.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://intevydis.com/vd-list.shtml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/38056",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1023465",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/61699",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/37829",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/0147",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://intevydis.blogspot.com/2010/01/zeus-web-server-ssl2clienthello.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://intevydis.com/vd-list.shtml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/38056",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1023465",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/61699",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/37829",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/0147",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in the SSLv2 support in Zeus Web Server before 4.3r5 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in an invalid Client Hello message."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer en el soporte SSLv2 en Zeus Web Server en versiones anteriores a v4.3r5 permite a atacantes remotos producir una denegación de servicio (caída de demonio) o posiblemente ejecutar código de forma arbitraria a través de una cadena larga en un mensaje invalido \"Client Hello\"."
    }
  ],
  "lastModified": "2026-06-16T23:15:59.603",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zeus:zeus_web_server:4.3r5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4FB721D6-3683-494F-9F0F-2B2C7368C51D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}