支持本站 — 捐款将帮助我们持续运营

目标: 1000 元,已筹: 1000

100.0%
获取后续新漏洞提醒登录后订阅
一、 漏洞 CVE-2024-7254 基础信息
漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Stack overflow in Protocol Buffers Java Lite
来源: 美国国家漏洞数据库 NVD
Vulnerability Description
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
来源: 美国国家漏洞数据库 NVD
CVSS Information
N/A
来源: 美国国家漏洞数据库 NVD
Vulnerability Type
未加控制的资源消耗(资源穷尽)
来源: 美国国家漏洞数据库 NVD
Vulnerability Title
Protocol Buffers 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Protocol Buffers是Protocol Buffers开源的一种 Google 的数据交换格式。 Protocol Buffers存在安全漏洞,该漏洞源于任何解析不受信任的协议缓冲区数据的项目都可能因缓冲区溢出而受到破坏。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD
受影响产品
厂商产品影响版本CPE订阅
GoogleProtocol Buffers 0 ~ 28.2 -
Googleprotobuf-java 0 ~ 3.25.5 -
Googleprotobuf-javalite 0 ~ 3.25.5 -
Googleprotobuf-kotlin 0 ~ 3.25.5 -
Googleprotobuf-kotllin-lite 0 ~ 3.25.5 -
Googlegoogle-protobuf [JRuby Gem] 0 ~ 3.25.5 -
二、漏洞 CVE-2024-7254 的公开POC
#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC
三、漏洞 CVE-2024-7254 的情报信息
Please 登录 to view more intelligence information
四、漏洞 CVE-2024-7254 的评论
匿名用户
2025-08-20 01:39:22

Hello Sir I hope this message finds you well. We are a distinguished financial hub based in the UAE. We specialize in providing non-collateral loans tailored for business expansion, particularly for portfolios demonstrating a strong return on investment. In addition to our lending services, we proudly serve as representatives for esteemed angel investors. These individuals are affluent and reputable private investors actively seeking compelling and promising investment opportunities to allocate their capital. Our client currently needs to invest the sum of 100 Million united states dollars in any viable enterprise that would yield an annual basic 15% ROI(Return on Investment). I look forward to the possibility of collaborating with you or your company in this very enterprising endeavour. Please contact us only at everestfinancecorp@gmail.com For further details Yours truly Credit Desk


发表评论