cgit 0.8.3.5之前版本的cgit.cgi的html.c中的convert_query_hexchar函数中存在off-by-one错误漏洞。远程攻击者可以借助由无效16进制字符之后的%字符组成的字符串,导致拒绝服务(无限循环)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2011-0284 | MIT Kerberos KDC 'do_as_req.c'双重释放内存破坏漏洞 | |
| CVE-2011-0421 | PHP Zip扩展_zip_name_locate函数拒绝服务漏洞 | |
| CVE-2011-0708 | PHP Exif扩展exif.c拒绝服务漏洞 | |
| CVE-2011-1024 | OpenLDAP back-ldap chain.c外部程序认证绕过漏洞 | |
| CVE-2011-1025 | OpenLDAP back-ndb bind.cpp访问限制绕过漏洞 | |
| CVE-2011-1081 | OpenLDAP slapd modrdn.c拒绝服务漏洞 | |
| CVE-2011-1464 | PHP strval函数缓冲区溢出漏洞 | |
| CVE-2011-1465 | Google Chrome net/http/http_network_transaction.cc SPDY实现拒绝服务漏洞 | |
| CVE-2011-1466 | PHP Calendar SdnToJulian函数整数溢出漏洞 | |
| CVE-2011-1467 | PHP Intl扩展NumberFormatter::setSymbol函数拒绝服务漏洞 | |
| CVE-2011-1468 | PHP OpenSSL扩展多个内存泄露漏洞 | |
| CVE-2011-1469 | PHP Streams组件拒绝服务漏洞 | |
| CVE-2011-1470 | PHP Zip扩展拒绝服务漏洞 | |
| CVE-2011-1471 | PHP Zip扩展zip_stream.c整数符号错误漏洞 |
No comments yet