Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2008-0045

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Mac OS X是苹果家族机器所使用的操作系统。 Apple 2008-002安全更新修复了Mac OS X中的多个安全漏洞,远程或本地攻击者可能利用这些漏洞造成多种威胁。 AFP服务器检查Kerberos主域名的方式存在错误,如果对AFP服务器使用了跨域认证的话,就可能允许非授权连接到服务器。

AI Predicted 6.8 Difficulty: Moderate EPSS 2.34% · P82
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2008-0045

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass cross-realm authentication via unknown manipulations of Kerberos principal realm names.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Apple Mac OS AFP服务器 Kerberos主域名跨域认证漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Mac OS X是苹果家族机器所使用的操作系统。 Apple 2008-002安全更新修复了Mac OS X中的多个安全漏洞,远程或本地攻击者可能利用这些漏洞造成多种威胁。 AFP服务器检查Kerberos主域名的方式存在错误,如果对AFP服务器使用了跨域认证的话,就可能允许非授权连接到服务器。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2008-0045

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-0045

登录查看更多情报信息。

Vendor Advisories for CVE-2008-0045 (7)

Mailing List Discussions for CVE-2008-0045 (1)

Other References for CVE-2008-0045 (1)

Same Patch Batch · n/a · 2008-03-18 · 39 CVEs total

CVE-2008-1383 Gentoo ssl-cert eclass信息泄露漏洞
CVE-2008-1000 Apple Mac OS 服务器目录遍历漏洞
CVE-2008-0044 Apple Mac OS AFP客户端 afp:// URL栈溢出漏洞
CVE-2008-0046 Apple Mac OS 德语版的应用防火墙为特定服务和应用设置访问漏洞
CVE-2008-0048 Apple Mac OS NSDocument API处理文件名栈溢出漏洞
CVE-2008-0049 Apple Mac OS NSApplication线程mach端口任意命令执行漏洞
CVE-2008-0050 Apple Safari HTTPS代理服务器可能在502 Bad Gateway安全欺骗漏洞
CVE-2008-0051 Apple Mac OS CoreFoundation处理整数溢出漏洞
CVE-2008-0057 Apple Mac OS 老式序列号格式的解析器多个整数溢出漏洞
CVE-2008-0997 Apple Mac OS AppKit处理PPD文件栈溢出漏洞
CVE-2008-0999 Apple Mac OS 磁盘格式(UDF)文件系统意外关闭漏洞
CVE-2008-1372 bzip2 'bzlib.c' 未明文件全文溢出漏洞
CVE-2008-1330 Novell GroupWise Windows客户端API共享文件夹邮件信息泄露漏洞
CVE-2008-1369 Sun SPARC Enterprise T5120 and T5220 Servers 'sshd_config文件'不安全默认配置漏洞
CVE-2008-1370 wildmary Yap Blog 'index.php' PHP远程文件包含漏洞
CVE-2008-1371 Drake CMS 'install/index.php' 完全路径遍历漏洞
CVE-2008-0727 IBM Informix Dynamic Server多个远程溢出漏洞
CVE-2008-0949 IBM Informix Dynamic Server 畸形连接请求安全权限漏洞
CVE-2008-1368 Microsoft Internet Explorer 代码注入漏洞
CVE-2008-0988 Apple Mac OS Libsystem的strnstr strnstr API的字节错误漏洞

Showing top 20 of 39 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-0045

No comments yet


Leave a comment