Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2008-3496

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。 Linux kernel 2.6.26.1之前版本中的video4linux(V4L)实现中的uvcvideo中的drivers/media/video/uvc/uvc_driver.c文件的uvc_parse_format函数在解析格式化描述符时存在缓冲区错误漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。

AI Predicted 7.2 Difficulty: Easy EPSS 3.28% · P87
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2008-3496

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Buffer overflow in format descriptor parsing in the uvc_parse_format function in drivers/media/video/uvc/uvc_driver.c in uvcvideo in the video4linux (V4L) implementation in the Linux kernel before 2.6.26.1 has unknown impact and attack vectors.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。 Linux kernel 2.6.26.1之前版本中的video4linux(V4L)实现中的uvcvideo中的drivers/media/video/uvc/uvc_driver.c文件的uvc_parse_format函数在解析格式化描述符时存在缓冲区错误漏洞。目前尚无此漏洞的相关信息,请随时关注CNNVD或厂商公告。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2008-3496

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-3496

登录查看更多情报信息。

Patches & Fixes for CVE-2008-3496 (1)

Vendor Advisories for CVE-2008-3496 (4)

Mailing List Discussions for CVE-2008-3496 (1)

Same Patch Batch · n/a · 2008-08-06 · 23 CVEs total

CVE-2008-3503 WebGUI Collaboration RSS 信息泄露漏洞
CVE-2008-3491 Scripts24 iPost及iTGP go.php SQL注入漏洞
CVE-2008-3490 E-topbiz OnlineDating mail.php SQL注入漏洞
CVE-2008-3489 PHPX includes/functions.inc.php SQL注入漏洞
CVE-2008-3488 Novell iManagerProperty 安全绕过漏洞
CVE-2008-3487 PHPAuction GPLEnhanced profile.php SQL注入漏洞
CVE-2008-3486 Coppermine PhotoGallery user_get_profile() 文件引用漏洞
CVE-2008-3485 Citrix MetaFramePresentationServer 本地权限提升漏洞
CVE-2008-3506 PolyPager nr参数 SQL注入漏洞
CVE-2008-3505 PolyPager nr参数 跨站脚本攻击漏洞
CVE-2008-3504 PHP File Manager 授权问题漏洞
CVE-2008-2939 Apache HTTP Server 跨站脚本漏洞
CVE-2008-3502 RT 'Devel::StackTrace' Perl Module 远程拒绝服务漏洞
CVE-2008-3501 Novell Groupwise WebAccess 跨站脚本攻击漏洞
CVE-2008-3500 Drupal SuggestedTerms模块 跨站脚本攻击漏洞
CVE-2008-3499 Ektron Cms4000.net 未明漏洞
CVE-2008-3498 nBill index.php SQL注入漏洞
CVE-2008-3497 MyPHPCMS pages.php SQL注入漏洞
CVE-2008-3495 PcsheyPortal kategori.asp SQL注入漏洞
CVE-2008-3494 m86security R3000 InternetFilter 绕过安全限制漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-3496

No comments yet


Leave a comment