SKCrypAX ActiveX控件是韩国银行、股票等在线银行服务常用的证书加密解决方案。 SKCrypAX ActiveX控件实现上存在缓冲区溢出漏洞,远程攻击者可能利用此漏洞控制用户机器。 SKCrypAX控件的DownloadCert()、DecryptFileByKey()和EncryptFileByKey()方法没有正确验证某些参数,如果对其传送了超长字符串的话就可能触发栈溢出,导致执行任意指令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2007-1949 | WebBlizzard CMS 会话固定漏洞 | |
| CVE-2007-1940 | IBM Tivoli Business Service Manager NCISETUP.DB及MSI.LOG文件明文口令泄露漏洞 | |
| CVE-2007-1941 | IBM Lotus Domino Web Access Active Content Filter 跨站脚本攻击漏洞 | |
| CVE-2007-1942 | FastStone Image Viewer 整数溢出漏洞 | |
| CVE-2007-1943 | ACDSee 9.0 Photo Manager 整数溢出漏洞 | |
| CVE-2007-1944 | IBM WebSphere Application Server Java Message Service拒绝服务漏洞 | |
| CVE-2007-1945 | IBM WebSphere Application Server Servlet Engine/Web Container未明漏洞 | |
| CVE-2007-1946 | Microsoft Windows Explorer 整数溢出漏洞 | |
| CVE-2007-1947 | Firebug extension DOM templates 跨站脚本攻击漏洞 | |
| CVE-2007-1948 | IrfanView 缓冲区溢出漏洞 | |
| CVE-2007-1971 | Gazi Okul Sitesi 'Fotokategori.ASP' SQL注入漏洞 | |
| CVE-2007-1950 | WebBlizzard CMS 'index_cms.php'跨站脚本攻击漏洞 | |
| CVE-2007-1951 | onelook obo Shop PHPSESSID 设置会话固定漏洞 | |
| CVE-2007-1952 | onebyone CMS 远程会话固定漏洞 | |
| CVE-2007-1953 | onelook courts on-line PHPSESSID cookie web会话固定漏洞 | |
| CVE-2007-1954 | ArchiveXpert 多个目录遍历漏洞 | |
| CVE-2007-1956 | Groupee UBB.Threads 'ubbthreads.php' SQL注入漏洞 | |
| CVE-2007-1957 | Guernion Sylvain Portail Web Php 多个PHP代码注入漏洞 | |
| CVE-2007-1357 | Linux Kernel AppleTalk atalk_sum_skb函数拒绝服务漏洞 | |
| CVE-2007-1962 | XOOPS WF-Snippets模块 'index.php'SQL注入漏洞 |
Showing top 20 of 39 CVEs. View all on vendor page → →
No comments yet