Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-1350

EPSS 81.25% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-1350

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Stack-based buffer overflow in webadmin.exe in Novell NetMail 3.5.2 allows remote attackers to execute arbitrary code via a long username during HTTP Basic authentication.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Novell NetMail HTTP基本认证超长用户名远程缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Novell NetMail是基于Internet标准消息和安全协议的邮件和日历系统。 Novell NetMail中默认绑定在TCP/89端口上的webadmin.exe进程处理用户认证请求存在栈溢出漏洞,远程攻击者可能利用此漏洞控制服务器。 由于不安全的sprintf()调用,如果在HTTP基本认证阶段发送了超过213字节的超长用户名,就会触发这个缓冲区溢出,导致执行任意指令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-1350

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-1350

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-03-08 · 12 CVEs total

CVE-2007-1359Mod_Security ASCIIZ字节绕过安全限制漏洞
CVE-2007-1360Drupal Nodefamily 模块 访问控制绕过漏洞
CVE-2007-1361VirtueMart virtuemart_parser.php 跨站脚本攻击漏洞
CVE-2007-1346Sun Ipmitool接口远程非授权访问漏洞
CVE-2007-1347Microsoft Windows Explorer Office文件摘要信息 拒绝服务攻击漏洞
CVE-2007-1339Monitor-Line Links Management Index.PHP SQL注入漏洞
CVE-2007-1340News-Letterman eintrag.php 远程文件包含漏洞
CVE-2007-1341Simple Invoices "include/auth/auth.php" 敏感信息泄露漏洞
CVE-2007-1342Jelsoft vBulletin "admincp/index.php" 跨站脚本攻击漏洞
CVE-2007-1343Craig Knudsen WebCalendar includes/functions.php文件 任意变量重写漏洞
CVE-2007-1344Ezstream 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2007-1350

No comments yet


Leave a comment