unicon-imc2是Debian操作系统中所使用的中文输入法库。 unicon-imc2在使用环境变量数据时存在缓冲区溢出漏洞,本地攻击者可能利用此漏洞提升自己的权限。 unicon-imc2库没有安全地使用HOME环境变量,如果用户使用了链接到该函数库的应用程序的话就可能触发缓冲区溢出,导致以root用户权限执行任意指令。漏洞代码位于/unicon/ImmModules/cce/CCE_pinyin.c文件中: static int IMM_Flush () { char name[256]; sp
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2007-3523 | XCMS 目录遍历漏洞 | |
| CVE-2007-3526 | Buddy Zone SQL注入漏洞 | |
| CVE-2007-3528 | Disk ARchive Blowfish-CBC加密实现IV冲突漏洞 | |
| CVE-2007-3511 | Mozilla FireFox OnKeyDown事件文件上传漏洞 | |
| CVE-2007-3512 | Lhaca File Archiver 缓冲区溢出漏洞 | |
| CVE-2007-3513 | Linux Kernel USBLCD内存耗尽拒绝服务漏洞 | |
| CVE-2007-3514 | Apple Safari 跨域漏洞 | |
| CVE-2007-2838 | GSAMBAD 不安全临时文件创建漏洞 | |
| CVE-2007-3530 | PHPDirector 权限漏洞 | |
| CVE-2007-3524 | Ripe Website Manager 多个文件包含漏洞 | |
| CVE-2007-3525 | Ripe Website Manager 远程攻击漏洞 | |
| CVE-2007-3522 | sPHPell 多个文件包含漏洞 | |
| CVE-2007-3521 | ArcadeBuilder Game Portal Manager SQL注入漏洞 | |
| CVE-2007-3520 | Easybe SQL注入漏洞 | |
| CVE-2007-3519 | phpEventCalendar SQL注入漏洞 | |
| CVE-2007-3518 | HispaH YouTube Clone Script SQL注入漏洞 | |
| CVE-2007-3517 | Claroline 跨站脚本漏洞 | |
| CVE-2007-3516 | Gorki Online Santrac Sitesi 跨站脚本漏洞 | |
| CVE-2007-3515 | TotalCalendar View_Event Script SQL注入漏洞 | |
| CVE-2007-2837 | Fireflier-Server 不安全临时文件创建漏洞 |
Showing top 20 of 46 CVEs. View all on vendor page → →
No comments yet