RealWin是运行在Windows平台上的数据采集与监视控制系统(SCADA)服务器产品。 如果远程攻击者向RealWin服务器发送了特制的FC_INFOTAG/SET_CONTROL报文的话,就可以触发栈溢出,导致执行任意代码。RealWin服务器使用专有协议接受来自FlewWin客户端的连接,无需拥有有效凭据便可以利用这个漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2008-4323 | Microsoft Windows Explorer畸形ZIP文件拒绝服务漏洞 | |
| CVE-2008-4324 | Mozilla Firefox用户界面事件调度器拒绝服务漏洞 | |
| CVE-2008-3827 | MPlayer demux_real.c 整数溢出漏洞 | |
| CVE-2008-4321 | FlashGet FTP PWD响应栈溢出漏洞 | |
| CVE-2008-4318 | Project Observer 执行任意指令漏洞 | |
| CVE-2008-4319 | Libra File Manager fileadmin.php认证绕过漏洞 | |
| CVE-2008-4320 | OpenNMS 多个跨站脚本攻击漏洞 | |
| CVE-2008-2474 | ABB PCU400 "x87" 缓冲区溢出漏洞 | |
| CVE-2008-3524 | Fedora initscripts 'rc.sysinit'任意文件上传漏洞 | |
| CVE-2008-4120 | FlatPress 多个跨站脚本攻击漏洞 | |
| CVE-2008-4192 | cman 'fence_egenera' 不安全临时文件创建漏洞 | |
| CVE-2008-4210 | Linux kernel fs/open.c权限提升和信息泄露漏洞 | |
| CVE-2008-4299 | Microsoft Internet Authentication service(IAS) iashlpr.dll大整数拒绝服务漏洞 | |
| CVE-2008-4300 | Microsoft Internet Information Services 输入验证错误漏洞 | |
| CVE-2008-4301 | Microsoft Internet Information Services 信任管理问题漏洞 | |
| CVE-2008-4302 | Linux kernel 资源管理错误漏洞 |
No comments yet