CoreHTTP是一款小型的Web服务器。 CoreHTTP没有对HTTP请求执行充分的输入验证,在src/http.c文件45和46行的sscanf()调用可能触发单字节溢出: 45: sscanf(parentsprock->buffer, 46: "%" PATHSIZE_S "[A-Za-z] %" PATHSIZE_S "s%*[ \t\n]", req, url); req和url缓冲区所声明的大小为256字节(PATHSIZE),但sscanf()调用可向这些缓冲区写入256字节(PATHS
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2009-4233 | Youjoomla YJ Whois 'mod_yj_whois.php'跨站脚本攻击漏洞 | |
| CVE-2009-3994 | denton_woods DevIL 'il_dicom.c' 栈缓冲溢出漏洞 | |
| CVE-2009-2843 | apple mac_os_x applets证书加密问题漏洞 | |
| CVE-2009-2749 | IBM WebSphere Application Server Communications Enabled Applications 加密问题漏洞 | |
| CVE-2009-4228 | xfig 'u_bound.c'缓冲区溢出漏洞 | |
| CVE-2009-4227 | Xfig和'f_readold.c'文件解析栈溢出漏洞 | |
| CVE-2009-4226 | sun opensolaris IP模块竞争条件错误漏洞 | |
| CVE-2009-4225 | CA eTrust PestPatrol'ppctl.dl'PestPatrol ActiveX控件栈缓冲溢出漏洞 | |
| CVE-2009-4235 | Tim_hockin acpid '/var/log/acpid'敏感信息泄露漏洞 | |
| CVE-2009-4234 | Micronet Network Access Controller 'error_user.shtml' 跨站脚本攻击漏洞 | |
| CVE-2009-1298 | linux kernel 'net/ipv4/ip_fragment.c'缓冲区溢出漏洞 | |
| CVE-2009-4232 | Jonijnm Kide Shoutbox 'index.php' 授权问题漏洞 | |
| CVE-2009-4231 | Basic-cms SweetRice 'plugins.php' 目录遍历漏洞 | |
| CVE-2009-4230 | ruven_pillay iipimage_server缓冲区溢出漏洞 | |
| CVE-2009-4229 | ActiveWebSoftwares Active Bids 多个SQL注入漏洞 | |
| CVE-2009-4033 | Tim_hockin acpid 权限许可和敏感信息泄露漏洞 | |
| CVE-2009-4236 | EC-CUBE 'LC_Page_Admin_Customer_SearchCustomer.php' 信息泄露漏洞 | |
| CVE-2009-3844 | HP OpenView Data Protector Application Recovery Manager栈缓冲区溢出漏洞 | |
| CVE-2009-1569 | Novell iPrint Client缓冲区溢出漏洞 | |
| CVE-2009-1568 | Novell iprint_client 'ienipp.ocx' 缓冲区溢出漏洞 |
No comments yet