CAPICOM.Certificates是一种ActiveX控件,允许脚本程序根据安全的基本Windows CryptoAPI功能加密数据。 CAPICOM.Certificates实现上存在输入验证漏洞,远程攻击者可能利用此漏洞控制用户机器。 Microsoft CAPICOM和BizTalk Server中的加密API组件对象模型证书ActiveX控件(CAPICOM.dll)处理某些用户输入时存在漏洞。如果传递了意外数据,则ActiveX控件可能失败,并允许远程执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2007-0945 | Microsoft IE属性方法远程代码执行漏洞 | |
| CVE-2007-2528 | Windows Trend Micro ServerProtect 'AgRpcCln.dll' 缓冲区溢出漏洞 | |
| CVE-2007-2527 | DynamicPAD 多个PHP远程文件包含漏洞 | |
| CVE-2007-2526 | SmartCode VNC Manager ActiveX Control 'Scvncctrl.DLL' 堆缓冲区溢出漏洞 | |
| CVE-2007-2525 | Linux Kernel PPPoE Socket 本地拒绝服务漏洞 | |
| CVE-2007-2524 | OTRS 'Index.PL' 跨站脚本攻击漏洞 | |
| CVE-2007-2508 | Trend Micro ServerProtect EarthAgent.exe远程栈缓冲区溢出漏洞 | |
| CVE-2007-2221 | Microsoft Windows mdsauth.dll控件远程代码执行漏洞 | |
| CVE-2007-1747 | Microsoft Office畸形绘图对象远程代码执行漏洞 | |
| CVE-2007-1202 | Microsoft Word RTF解析远程堆破坏漏洞 | |
| CVE-2007-0947 | Microsoft IE HTML对象脚本错误远程代码执行漏洞 | |
| CVE-2007-0946 | Microsoft IE HTML对象脚本错误远程代码执行漏洞 | |
| CVE-2007-2521 | E-Gads! 'Common.PHP' 远程文件包含漏洞 | |
| CVE-2007-0944 | Microsoft IE表格列删除内存破坏漏洞 | |
| CVE-2007-0942 | Microsoft IE CHTSKDIC.DLL任意代码执行漏洞 | |
| CVE-2007-0323 | Research In Motion Blackberry TeamOn Import Object ActiveX控件缓冲区溢出漏洞 | |
| CVE-2007-0221 | Microsoft Exchange IMAP命令处理远程拒绝服务漏洞 | |
| CVE-2007-0220 | Microsoft Outlook Web Access远程脚本注入漏洞 | |
| CVE-2007-0213 | Microsoft Exchange Base64 MIME消息远程代码执行漏洞 | |
| CVE-2007-0039 | Microsoft Exchange iCal 代码问题漏洞 |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet