CVE-2010-2362
Estado: ModificadaAlta (10)—
Winny 2.0b7.1 and earlier does not properly process node information, which has unspecified impact and remote attack vectors that might lead to use of the product's host for DDoS attacks.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.45%
- Percentil entre todas las CVEs puntuadas: 72
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-20
Referencias
- http://jvn.jp/en/jp/JVN25393522/index.html
- http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000028.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61277
- http://jvn.jp/en/jp/JVN25393522/index.html
- http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000028.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/61277
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-2362",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-08-25T20:00:17.097",
"references": [
{
"url": "http://jvn.jp/en/jp/JVN25393522/index.html",
"source": "cve@mitre.org"
},
{
"url": "http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000028.html",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61277",
"source": "cve@mitre.org"
},
{
"url": "http://jvn.jp/en/jp/JVN25393522/index.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000028.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/61277",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Winny 2.0b7.1 and earlier does not properly process node information, which has unspecified impact and remote attack vectors that might lead to use of the product's host for DDoS attacks."
},
{
"lang": "es",
"value": "Winny v2.0b7.1 y anteriores no procesa de forma adecuada la información del nodo, esto tiene un impacto y vectores remotos de ataque no especificados que pueden conllevar a que se utilice el ordenador que aloja el producto para realizar ataques Distribuidos de Denegación de Servicio (DDoS)."
}
],
"lastModified": "2026-06-16T23:20:37.217",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:winny:winny:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F143B54-0121-4F08-A5B6-588A1A8F1DCB",
"versionEndIncluding": "2.0b7.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}