Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remote attackers to execute arbitrary code via a long string in the second argument to the AddRouteEntry method.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SonicWALL SSL VPN客户端ActiveX控件栈缓冲区溢出漏洞
Vulnerability Description
SonicWALL SSL-VPN可以为企业网络提供简单易用的VPN解决方案。 SonicWALL SSL-VPN的ActiveX控件实现上存在栈缓冲区溢出漏洞,允许攻击者删除客户端上的任意文件;此外NELaunchCtrl ActiveX控件的AddRouteEntry()方式在处理第二个参数时未经长度检查便拷贝到了栈缓冲区,使用以下方式便可以将进程跳转到UVWX域: o.AddRouteEntry ("", "ABCDEFGHIJKLMNOPQRSTUVWX"); 以下属性还受Unicode溢出的影响
CVSS Information
N/A
Vulnerability Type
N/A