snappy-java 1.1.10.8 及之前版本存在一个缓冲区溢出漏洞,位于 方法中。该漏洞会导致数据被写入目标缓冲区的末尾之后。攻击者可以提供不可压缩的数据,使其大小超过目标缓冲区剩余容量,从而破坏堆外内存(off-heap memory),并导致 JVM 进程终止。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| xerial | snappy-java | ≤ 1.1.10.8 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| xerial | snappy-java | 0 ~ 1.1.10.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet