Rizin是Rizin组织的一个免费的开源逆向工程框架。用于分析二进制文件、反汇编代码、调试程序、作为取证工具、作为能够打开磁盘文件的可编写脚本的命令行十六进制编辑器等等。 Rizin 0.4.0 及之前版本存在缓冲区错误漏洞,该漏洞源于从 dyld 缓存文件获取数据时,容易受到越界写入的影响,攻击者利用该漏洞可以在用户的计算机上执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-36039 | 7.8 HIGH | Out-of-bounds write when parsing DEX files in Rizin |
| CVE-2022-36040 | 7.8 HIGH | Rizin Out-of-bounds Write vulnerability in pyc/marshal.c |
| CVE-2022-36041 | 7.8 HIGH | Rizin Out-of-bounds Write vulnerability in Mach-O binary plugin |
| CVE-2022-36043 | 7.8 HIGH | Rizin Double Free in bobj.c when using qnx binary plugin |
| CVE-2022-36044 | 7.8 HIGH | Rizin Out-of-bounds Write vulnerability in Lua binary plugin |
No comments yet