在 FLVMeta 1.2.2 及更早版本中发现了一个漏洞。受影响的是组件“AMF 字符串处理”中文件 的 函数。对参数 的处理会导致堆缓冲区溢出。该攻击可远程发起。利用该漏洞的利用方式已公开,且可能被使用。用于修复该问题的补丁编号为 。应应用该补丁以修复此问题。项目维护者对该漏洞的安全影响表示怀疑:“虽然我承认这些 bug 并提供了修复,但我尚未看到任何可利用这些所谓漏洞的方式。”
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | FLVMeta | 1.2.0 |
cpe:2.3:a:flvmeta:flvmeta:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82608 | 7.4 HIGH | Kamailio AVP cxdx_avp.c get_4bytes out-of-bounds |
| CVE-2026-82630 | 7.3 HIGH | PowerJob Transport Endpoint TestController.java MuConnectionManager.getOrCreateConnection |
| CVE-2026-82598 | 7.3 HIGH | SeaCMS Template search.php parseIf code injection |
| CVE-2026-82600 | 7.3 HIGH | SeaCMS zyapi.php sql injection |
| CVE-2026-82603 | 5.4 MEDIUM | SeaCMS Comment Cache member.php del_pl path traversal |
| CVE-2026-82599 | 5.4 MEDIUM | SeaCMS Avatar Upload member.php unlink path traversal |
| CVE-2026-82623 | 5.3 MEDIUM | open62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange |
| CVE-2026-82602 | 5.3 MEDIUM | SeaCMS ass.php authorization |
| CVE-2026-82805 | 4.3 MEDIUM | Typora Mermaid Rendering cross site scripting |
| CVE-2026-82821 | 4.3 MEDIUM | FLVMeta AMF Object Parsing amf.c amf_object_get null pointer dereference |
| CVE-2026-82601 | 4.3 MEDIUM | SeaCMS err.php cross site scripting |
| CVE-2026-82596 | 3.3 LOW | LatencyUtils PauseDetector LatencyStats.java LatencyStats.recordDetectedPause memory corru |
| CVE-2026-51717 | TOTOLINK T6 4.1.5 未认证访问控制缺陷 | |
| CVE-2026-51715 | TOTO Link T6 4.1.5未授权MAC过滤删除漏洞 | |
| CVE-2026-51716 | TOTOLINK T6 4.1.5端口转发规则未授权删除 | |
| CVE-2026-51713 | TOTOLINK T6 4.1.5 访问控制不当漏洞 | |
| CVE-2026-51714 | TOTOLINK T6 4.1.5 未认证访问控制缺陷 | |
| CVE-2026-51718 | TOTOLINK T6 4.1.5 未认证访问控制缺陷 | |
| CVE-2026-51704 | TOTOLINK T6 4.1.5 未授权访问控制漏洞 | |
| CVE-2026-51720 | TOTOLINK T6 4.1.5未授权访问控制缺陷 |
Showing top 20 of 87 CVEs. View all on vendor page → →
No comments yet