← Vulnerability feed

Vulnerability record · CVE-2010-0361 · published 20 January 2010

CVE-2010-0361: Sun Java System Web Server WebDAV stack buffer overflow via long URI

Sun · Java System Web Server

Sun Java System Web Server 7.0 Update 7 contains a stack-based buffer overflow in the WebDAV implementation of webservd. A remote attacker can send an HTTP OPTIONS request with an overly long URI to crash the daemon and possibly achieve other unspecified impact. The flaw is remotely reachable without authentication and carries a maximum CVSS v2 score.

10.0 CVSS 2.0 High EPSS 80% · top 0.4% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
80%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long URI in an HTTP OPTIONS request.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityMaximum CVSS v2 score, unauthenticated remote reachability, public exploit references, and very high EPSS probability make this a top remediation priority.

What it is

Sun Java System Web Server 7.0 Update 7 contains a stack-based buffer overflow in the WebDAV implementation of webservd. A remote attacker can send an HTTP OPTIONS request with an overly long URI to crash the daemon and possibly achieve other unspecified impact. The flaw is remotely reachable without authentication and carries a maximum CVSS v2 score.

Impact

An attacker can cause a denial of service by crashing the webservd daemon; the record also notes possible unspecified other impact, which could include code execution, but this is not confirmed in the description.

Attack surface

Reachable over the network through the WebDAV HTTP interface by sending a crafted OPTIONS request with a long URI. No authentication or user interaction is required per the CVSS vector (AV:N/AC:L/Au:N).

Exploitation

No CISA KEV listing, but EPSS is 0.80521 (99.6th percentile) and both references are tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the vendor patch or upgrade Sun Java System Web Server beyond 7.0 Update 7.
  • Disable WebDAV if it is not required for business operations.
  • Restrict network access to the WebDAV service using firewall rules or reverse proxy filtering.
  • Enforce URI length limits at the reverse proxy or web server layer to block oversized requests.
  • Monitor for and block malformed OPTIONS requests with abnormally long URIs.

Detection

  • Inspect web server and proxy logs for HTTP OPTIONS requests with unusually long URIs.
  • Alert on webservd crashes or unexpected restarts correlated with WebDAV traffic.
  • Use network IDS signatures for oversized OPTIONS request URIs targeting WebDAV endpoints.
  • Baseline normal URI lengths and flag outliers in WebDAV request paths.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-0361 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-0360Sun java system web server improper input validation vulnerabilitySun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to overwrite memory locations in the heap, and discover the contents of me…EPSS 3.1%10.0CVE-2000-0812Sun java system web server vulnerabilityThe administration module in Sun Java web server allows remote attackers to execute arbitrary commands by uploading Java code to the module and invok…EPSS 6.0%9.3CVE-2009-3878Sun java system web server memory buffer overflow vulnerabilityBuffer overflow in Sun Java System Web Server 7.0 Update 6 has unspecified impact and remote attack vectors, as demonstrated by the vd_sjws module in…EPSS 2.5%9.3CVE-2007-3715Sun java system application server improper input validation vulnerabilitySun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML …EPSS 2.3%7.5CVE-2010-0387Sun java system web server memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in (1) webservd and (2) the admin server in Sun Java System Web Server 7.0 Update 7 allow remote attackers to ca…EPSS 7.7%7.5CVE-2010-0388Sun java system web server vulnerabilityFormat string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a de…EPSS 7.2%7.5CVE-2010-0272Sun java system web server memory buffer overflow vulnerabilityHeap-based buffer overflow in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to discover process memory locations via craft…EPSS 2.5%7.5CVE-2010-0273Sun java system web server vulnerabilityUnspecified vulnerability in Sun Java System Web Server 7.0 Update 6 on Linux allows remote attackers to execute arbitrary code by sending a process …EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2010-0361), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.