漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tencent WeChat 2.9.5 desktop version. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the WXAM decoder. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-11907.
CVSS Information
N/A
Vulnerability Type
跨界内存读
Vulnerability Title
Tencent WeChat 缓冲区错误漏洞
Vulnerability Description
Tencent WeChat(微信)是中国腾讯(Tencent)公司的一款在线社交应用程序。该程序支持发送语音短信、视频、图片和文字等。 Tencent WeChat 2.9.5 desktop version 存在安全漏洞,该漏洞允许远程攻击者泄露敏感信息。攻击者可利用该漏洞,再结合其他漏洞,在当前进程的上下文中执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A