Cool Projects TarDiff是软件开发者Josef Spillner所研发的一套压缩包工具。 Cool Projects TarDiff中存在安全漏洞,该漏洞源于tarballs解包文件使用可预测的临时目录。本地攻击者可通过对目录中的路径实施符号链接攻击利用该漏洞写入任意文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2015-0857 | Cool Projects TarDiff 命令注入漏洞 | |
| CVE-2015-8863 | jq 基于堆的缓冲区溢出漏洞 | |
| CVE-2015-8868 | Poppler 基于堆的缓冲区溢出漏洞 | |
| CVE-2016-2094 | HTTPS NIO Connector 拒绝服务漏洞 | |
| CVE-2016-4074 | stedolan jq 缓冲区错误漏洞 | |
| CVE-2016-4422 | libpam-sshauth 本地提权漏洞 |
No comments yet