GNU cpio是美国GNU基金会开源的一款文件归档与提取工具。 GNU cpio 2.15及之前版本存在输出处理不当漏洞,该漏洞源于归档成员列表功能对输出编码或转义不当,可能导致攻击者构造包含换行符或ANSI转义序列的cpio归档,造成伪造列表条目或终端控制序列注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71392 | 5.3 MEDIUM | Integer Overflow in GNU Emacs for Android |
| CVE-2026-71393 | 5.3 MEDIUM | Heap Buffer Overflow in GNU Emacs for Android |
| CVE-2026-71391 | 5.3 MEDIUM | Off-by-One Error in GNU Emacs for Android |
| CVE-2026-71394 | 5.3 MEDIUM | Heap Use of Uninitialized Memory in GNU Emacs for Android |
| CVE-2026-66484 | 4.6 MEDIUM | Path Traversal in GNU cpio |
| CVE-2026-66485 | 4.6 MEDIUM | Uncontrolled Memory Allocation in GNU cpio |
No comments yet