Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-0454

EPSS 4.41% · P89
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-0454

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Format string vulnerability in the afsacl.so VFS module in Samba 3.0.6 through 3.0.23d allows context-dependent attackers to execute arbitrary code via format string specifiers in a filename on an AFS file system, which is not properly handled during Windows ACL mapping.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Samba服务器VFS插件afsacl.so远程格式串处理漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Samba是Samba团队开发的一套可使UNIX系列的操作系统与微软Windows操作系统的SMB/CIFS网络协议做连结的自由软件。该软件支持共享打印机、互相传输资料文件等。 Samba的VFS插件afsacl.so库在处理文件名时存在格式串漏洞,攻击者可能利用此漏洞诱使用户处理恶意的VFS分区控制服务器。 Samba在调用snprintf()时将磁盘上所储存的文件名用作了格式串,如果用户能够写入的共享使用Samba的afsacl.so库对AFS文件系统上的文件设置Windows NT访问控制列表的话,
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-0454

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-0454

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-02-06 · 38 CVEs total

CVE-2007-0763F3Site Index.PHP HTML注入漏洞
CVE-2007-0452Samba延迟CIFS文件打开拒绝服务漏洞
CVE-2007-0453Samba NSS主机查询Winbind多个远程缓冲区溢出漏洞
CVE-2007-0756Chicken VNC 远程拒绝服务漏洞
CVE-2007-0757DreamStats System Rootpath 'index.php' PHP远程文件包含漏洞
CVE-2007-0758PHPProbid 'lang.php' 远程文件包含漏洞
CVE-2007-0759EasyMoblog 多个SQL注入漏洞
CVE-2007-0760EQDKP Backup.PHP 权限绕过漏洞
CVE-2007-0761phpBB ezBoard converter 'config.php'PHP远程文件包含漏洞
CVE-2007-0762phpBB++ PHPBB_Root_Path 'includes/functions.php'PHP远程文件包含漏洞
CVE-2006-6968Phorum 群体适度控制中心页跨站脚本攻击漏洞
CVE-2007-0764F3Site 任意文件上传漏洞
CVE-2007-0765Curium CMS News.PHP SQL注入漏洞
CVE-2007-0766Remotesoft .NET Explorer 栈缓冲区溢出漏洞
CVE-2007-0767Phorum 内核跨站脚本攻击漏洞
CVE-2007-0768Yahoo! Messenger Notification Message HTML注入漏洞
CVE-2007-0769Phorum Register.PHP HTML注入漏洞
CVE-2007-0555PostgreSQL 安全漏洞
CVE-2007-0556PostgreSQL query planner拒绝服务漏洞
CVE-2007-0792Mozilla Bugzilla HTML mod_perl注入及信息泄露漏洞

Showing top 20 of 38 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-0454

No comments yet


Leave a comment