6.9

CVE-2010-1592

Exploit
sandra.sys 15.18.1.1 and earlier in the Sandra Device Driver in SiSoftware Sandra 16.10.2010.1 and earlier allows local users to gain privileges or cause a denial of service (system crash) via unspecified vectors involving "Model-Specific Registers."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SisoftwareSandra Version <= 16.10.2010.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.43% 0.343
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.9 3.4 10
AV:L/AC:M/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://osvdb.org/61947
http://secunia.com/advisories/38212
Vendor Advisory
http://www.ntinternals.org/ntiadv0808/ntiadv0808.html
Exploit
http://www.vupen.com/english/advisories/2010/0223
Vendor Advisory