AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2010-3595

HIGH · CVSS 7.8 EPSS 11.93% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2011-01-19 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

Exhibit — Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2010-3595
Severity
HIGH
CVSS
7.8
EPSS
11.93%
Oracle

Original Filing — NVD Description

Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality via unknown vectors related to Import Server. NOTE: the previous information was obtained from the January 2011 CPU. Oracle has not commented on claims from the original researcher that remote attackers can read arbitrary files via a full pathname in the first argument to the ImportBodyText method in the EasyMail ActiveX control (emsmtp.dll).