librsvg是GNOME项目的将 SVG 图像渲染到 Cairo 表面的库。GNOME 使用它来呈现 SVG 图标。在 GNOME 之外,其他桌面环境也将其用于类似目的。维基媒体将其用于维基百科的 SVG 图表。 librsvg 2.56.3之前版本存在安全漏洞,该漏洞源于URL解码器中存在目录遍历问题,攻击者可能会利用该漏洞泄露文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E5%85%B6%E4%BB%96%E6%BC%8F%E6%B4%9E/librsvg%20XInclude%20%E6%96%87%E4%BB%B6%E5%8C%85%E5%90%AB%E6%BC%8F%E6%B4%9E%20CVE-2023-38633.md | POC Details |
| 2 | https://github.com/vulhub/vulhub/blob/master/librsvg/CVE-2023-38633/README.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2023-3837 | 2.4 LOW | DedeBIZ sys_sql_query.php cross site scripting |
| CVE-2023-38195 | Datalust Seq 安全漏洞 |
No comments yet