← Back

CVE-2010-2448

nvd nist
Published: Jul 12, 2010Modified: Apr 29, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:N/A:P
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

znc.cpp in ZNC before 0.092 allows remote authenticated users to cause a denial of service (crash) by requesting traffic statistics when there is an active unauthenticated connection, which triggers a NULL pointer dereference, as demonstrated using (1) a traffic link in the web administration pages or (2) the traffic command in the /znc shell.

Affected (23)

Products: Znc: Znc
1 product
Znc
Configuration A
23 vulnerable
Vulnerable SoftwareAffected Versions
Znc
Up to 0.090
Version 0.034
Version 0.041
Version 0.043
Version 0.044
Version 0.045
Version 0.047
Version 0.050
Version 0.052
Version 0.054
Version 0.056
Version 0.058
Version 0.060
Version 0.062
Version 0.064
Version 0.066
Version 0.068
Version 0.070
Version 0.072
Version 0.074
Version 0.076
Version 0.078
Version 0.080

References (22)

Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.