← Vulnerability feed

Vulnerability record · CVE-2010-4435 · published 19 January 2011

CVE-2010-4435: Sunos vulnerability

Sun · Sunos

Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to CDE Calendar Manager Service Daemon and RPC. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from other software vendors that this affects other operating systems, such as HP-UX, or claims from a reliable third party that this is a buffer overflow in rpc.cmsd via long XDR-encoded ASCII strings in RPC call 10.

10.0 CVSS 2.0 High EPSS 14% · top 3.5%
10.0CVSS 2.0 base score
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
36References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in Oracle Solaris 8, 9, and 10 allows remote attackers to affect confidentiality, integrity, and availability, related to CDE Calendar Manager Service Daemon and RPC. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from other software vendors that this affects other operating systems, such as HP-UX, or claims from a reliable third party that this is a buffer overflow in rpc.cmsd via long XDR-encoded ASCII strings in RPC call 10.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://aix.software.ibm.com/aix/efixes/security/cmsd_advisory.asc
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02702395
http://osvdb.org/70569
http://secunia.com/advisories/42984 Vendor Advisory
http://secunia.com/advisories/43258 Vendor Advisory
http://securityreason.com/securityalert/8069
http://www.exploit-db.com/exploits/16137 Exploit
http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html Vendor Advisory
http://www.securityfocus.com/archive/1/516284/100/0/threaded
http://www.securityfocus.com/archive/1/516304/100/0/threaded
http://www.securityfocus.com/bid/45853
http://www.securityfocus.com/bid/46261
http://www.securitytracker.com/id?1024975
http://www.vupen.com/english/advisories/2011/0151 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0352 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-11-062/
https://exchange.xforce.ibmcloud.com/vulnerabilities/64797
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12794
http://aix.software.ibm.com/aix/efixes/security/cmsd_advisory.asc
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02702395
http://osvdb.org/70569
http://secunia.com/advisories/42984 Vendor Advisory
http://secunia.com/advisories/43258 Vendor Advisory
http://securityreason.com/securityalert/8069
http://www.exploit-db.com/exploits/16137 Exploit
http://www.oracle.com/technetwork/topics/security/cpujan2011-194091.html Vendor Advisory
http://www.securityfocus.com/archive/1/516284/100/0/threaded
http://www.securityfocus.com/archive/1/516304/100/0/threaded
http://www.securityfocus.com/bid/45853
http://www.securityfocus.com/bid/46261
http://www.securitytracker.com/id?1024975
http://www.vupen.com/english/advisories/2011/0151 Vendor Advisory
http://www.vupen.com/english/advisories/2011/0352 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-11-062/
https://exchange.xforce.ibmcloud.com/vulnerabilities/64797
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12794

Track CVE-2010-4435 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-4619Sunos vulnerabilityThe RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in progra…EPSS 12%10.0CVE-2008-2144Sunos vulnerabilityMultiple unspecified vulnerabilities in Solaris print service for Sun Solaris 8, 9, and 10 allow remote attackers to cause a denial of service or exe…EPSS 16%10.0CVE-2008-1369Sunos permissions and access controls vulnerabilityA certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that confi…EPSS 2.6%10.0CVE-2007-3093Sun solaris vulnerabilityUnspecified vulnerability in the logging mechanism in Solaris Management Console (SMC) on Sun Solaris 8 through 10 before 20070605 allows remote atta…EPSS 4.7%10.0CVE-2007-0882Solaris telnet daemon argument injection bypasses authenticationThe telnet daemon (in.telnetd) in Solaris 10 and 11 mishandles certain client-supplied "-f" sequences, passing them to the login program as a request…EPSS 98%analysed10.0CVE-2004-1351Sun solaris vulnerabilityUnknown vulnerability in the rwho daemon (in.rwhod) for Solaris 7 through 9 allows remote attackers to execute arbitrary code.EPSS 6.0%10.0CVE-2004-0523Mit kerberos vulnerabilityMultiple buffer overflows in krb5_aname_to_localname for MIT Kerberos 5 (krb5) 1.3.3 and earlier allow remote attackers to execute arbitrary code as …EPSS 12%10.0CVE-2003-0694Sendmail prescan buffer overflow allows remote code executionThe prescan function in Sendmail 8.12.9 contains a buffer overflow reachable through crafted email addresses, as demonstrated via the parseaddr funct…EPSS 66%analysed

Source: NIST National Vulnerability Database (record CVE-2010-4435), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.