7-Zip for Windows是一套基于Windows平台的免费的、开源的压缩/解压缩软件。 基于Windows平台的7-Zip 18.01及之前版本中存在安全漏洞,该漏洞源于程序通过调用‘LsaAddAccountRights’函数实现‘较大内存页面’选项,来向用户账户添加SeLockMemoryPrivilege权限。攻击者可通过使用SeLockMemoryPrivilege权限利用该漏洞绕过访问限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2017-10140 | Postfix Berkeley DB 安全漏洞 | |
| CVE-2018-10122 | QingDao Nature Easy Soft Chanzhi Enterprise Portal System 安全漏洞 | |
| CVE-2018-10106 | D-Link DIR-815 REV. B 安全漏洞 | |
| CVE-2018-10107 | D-Link DIR-815 REV. B 跨站脚本漏洞 | |
| CVE-2018-10108 | D-Link DIR-815 REV. B 跨站脚本漏洞 | |
| CVE-2018-10124 | Linux kernel 安全漏洞 | |
| CVE-2018-10133 | PbootCMS 安全漏洞 | |
| CVE-2018-10132 | PbootCMS 跨站请求伪造漏洞 | |
| CVE-2018-10128 | XYHCMS 跨站脚本漏洞 | |
| CVE-2018-10127 | XYHCMS 跨站请求伪造漏洞 | |
| CVE-2018-10177 | ImageMagick 安全漏洞 | |
| CVE-2018-10137 | IScripts UberforX Admin Panel 跨站请求伪造漏洞 | |
| CVE-2018-10136 | IScripts UberforX Admin Panel 跨站脚本漏洞 | |
| CVE-2018-10135 | IScripts eSwap User Panel 跨站脚本漏洞 | |
| CVE-2015-1952 | IBM AppScan Enterprise Edition 跨站脚本漏洞 | |
| CVE-2018-10138 | DNN CATALooK.netStore模块跨站脚本漏洞 | |
| CVE-2018-10170 | NordVPN for Windows 权限许可和访问控制问题漏洞 | |
| CVE-2018-10169 | ProtonVPN for Windows 权限许可和访问控制问题漏洞 | |
| CVE-2018-10070 | MikroTik 安全漏洞 |
No comments yet