CVE detail
CVE-2010-1885
The MPC::HexToNum function in helpctr.exe in Microsoft Windows Help and Support Center in Windows XP and Windows Server 2003 does not properly handle malformed escape sequences, which allows remote attackers to bypass the trusted documents whitelist (fromHCP option) and execute arbitrary commands via a crafted hcp:// URL, aka "Help Center URL Validation Vulnerability."
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
5 source links · newest first
After a period of steady decline that started in 2009, the number of application vulnerabilities has seen a significant increase during the first half of 2012, according to the latest version of Microsoft’s Security Intelligence Report (SIR) that was released on Tuesday. Exploits for security flaws in popular applications like Java and document readers were […]
newswww.csoonline.comOct 9, 2012, 3:00 PM- Fake AT&T wireless bill links to malwareHelp Net Security
Large outbreaks of phony AT&T wireless emails have been distributed in the last two days, according to Commtouch. The emails describe very large balances ($943 in the example below), that are sure to get aggravated customers clicking on the included links. Every link in the email leads to a different compromised site with malware hidden inside. The pattern is: legitimate domain / recurring set of random letters / index.html The index.html file tries to exploit … More →
newswww.helpnetsecurity.comApr 5, 2012, 4:16 AM - This is how Windows get infected with malwareHelp Net Security
When a Microsoft Windows machine gets infected by viruses/malware it does so mainly because users forget to update the Java JRE, Adobe Reader/Acrobat and Adobe Flash. This is revealed by a survey conducted by CSIS Security Group A/S. Basis of the study CSIS has over a period of almost three months actively collected real time data from various so-called exploit kits. An exploit kit is a commercial hacker toolbox that is actively exploited by computer … More →
newswww.helpnetsecurity.comOct 5, 2011, 7:07 AM - ‘Do-it-Yourself’ Botnet Kits Gain MomentumSecurityWeek
Fortinet released its August 2010 Threat Landscape report showing some interesting changes and shifts from previous months, with an interesting trend in “Do-It-Yourself” Botnet Kits gaining momentum and becoming a serious threat.
newswww.securityweek.comSep 1, 2010, 4:47 PM - Infected legitimate websites outscore adult 99:1Help Net Security
For every infected adult domain identified, there are 99 others with perfectly legitimate content that are also infected, according to a report by Avast. In the UK for example, there are more infected domains containing the word “London” than any other domain containing the word “sex”. The latest discovery of an infected site is the Vodafone UK website. This infection in the smart phones section shows how advanced the bad guys are at finding ways … More →
newswww.helpnetsecurity.comJun 30, 2010, 8:22 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2007-4041CVSS 6.8 · Medium
Multiple argument injection vulnerabilities in Mozilla Firefox 2.0.0.5 and 3.0alpha allow remote attackers to execute arbitrary commands via a NULL byte (%00) and shell metacharac…
- CVE-2012-2556CVSS 9.3 · Critical
The OpenType Font (OTF) driver in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1,…
- CVE-2012-0175CVSS 8.8 · High
The Shell in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attack…
- CVE-2012-1882CVSS 4.3 · Medium
Microsoft Internet Explorer 6 through 9 does not block cross-domain scrolling events, which allows remote attackers to read content from a different (1) domain or (2) zone via a c…
- CVE-2012-1880CVSS 9.3 · Critical
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "ins…
- CVE-2012-1879CVSS 8.1 · High
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by attempting to access an undefined me…