systemd是德国软件开发者Lennart Poettering和其他人共同研发的一款基于Linux的系统和服务管理器,它兼容了SysV和LSB的启动脚本,且提供了一个用来表示系统服务间依赖关系的框架。 systemd 37及之前版本的systemd-logind中的login/logind-session.c文件的‘session_link_x11_socket’函数存在安全漏洞。本地攻击者可通过对/run/user/目录下的X11用户目录实施符号链接攻击利用该漏洞创建或覆盖任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2014-2522 | Haxx CURL和Libcurl 输入验证漏洞 | |
| CVE-2014-2856 | Apple Common Unix Printing System 跨站脚本漏洞 | |
| CVE-2014-2844 | F-Secure Messaging Secure Gateway 跨站脚本漏洞 | |
| CVE-2014-0150 | QEMU‘virtio_net_handle_mac’函数整数溢出漏洞 | |
| CVE-2013-7369 | 多款F-Secure产品SQL注入漏洞 | |
| CVE-2013-4290 | OpenJPEG 基于栈的缓冲区错误漏洞 | |
| CVE-2013-4289 | OpenJPEG 整数溢出漏洞 | |
| CVE-2012-6646 | F-Secure Anti-Virus/Safe Anywhere/PSB Workstation Security | |
| CVE-2014-2597 | PCNetSoftware RAC Server 拒绝服务漏洞 | |
| CVE-2013-4279 | imapsync 信息泄露漏洞 | |
| CVE-2014-2289 | Digium Asterisk Open Source 输入验证漏洞 | |
| CVE-2014-2288 | Digium Asterisk Open Source 输入验证漏洞 | |
| CVE-2014-2287 | Digium Asterisk Open Source和Certified Asterisk 输入验证漏洞 | |
| CVE-2014-2286 | Digium Asterisk Open Source和Certified Asterisk 输入验证漏洞 | |
| CVE-2014-2014 | imapsync SSL/TLS Certificate 信任管理问题漏洞 | |
| CVE-2013-7196 | PHPFox 权限许可和访问控制漏洞 | |
| CVE-2013-7195 | PHPFox 权限许可和访问控制漏洞 |
No comments yet