CVE-2010-5333 is a stack-based buffer overflow in the web server component of Integard Pro and Integard Home before 2.0.0.9037, and in the 2.2.x branch before 2.2.0.9037. The flaw is triggered by sending an administration login POST request containing an overly long password value. Processing of the password does not properly enforce bounds, allowing memory corruption. The issue can be exploited through an EIP-overwrite buffer overflow condition, and the available context notes that an SEH-overwrite overflow also already existed in the vulnerable software. Successful exploitation can lead to arbitrary code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting a stack buffer overflow vulnerability (CVE-2010-5333) in the administration web interface of Race River's Integard Home/Pro internet content filter for Windows. The exploit targets the /LoginAdmin HTTP endpoint on TCP port 18881, sending a specially crafted POST request with an overlong password field to trigger the overflow. The module supports automatic version detection by requesting /banner.jpg and checking the Content-Length, allowing it to select the correct return address for different vulnerable versions. The payload is customizable (up to 2000 bytes, avoiding specific bad characters) and is executed with SYSTEM privileges if successful. The exploit is operational and leverages Metasploit's payload framework, making it easy to use for arbitrary code execution. The repository is structured as a single Ruby file within the Metasploit framework's exploit modules directory.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.