Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-4512

EPSS 0.69% · P72
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-4512

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Cross-site scripting (XSS) vulnerability in Sophos Anti-Virus for Windows 6.x before 6.5.8 and 7.x before 7.0.1 allows remote attackers to inject arbitrary web script or HTML via an archive with a file that matches a virus signature and has a crafted filename that is not properly handled by the print function in SavMain.exe.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Sophos Anti-Virus ZIP文档处理跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Sophos Anti-Virus是英国Sophos公司的一套适用于多种操作系统的反病毒软件。该软件可实时侦测和清除病毒、间谍软件、木马和蠕虫,确保台式机和笔记本电脑的全面网络保护。 如果ZIP文档中的病毒特征包含有畸形文件名的话,就可能在Sophos AntiVirus客户端触发跨站脚本漏洞。当Sophos anti-virus扫描到该ZIP文档时,会内部记录下可导致跨站脚本的畸形字符串,之后在通过Sophos客户端(SavMain.exe)访问这些信息时,就会解码跨站脚本攻击的字符串,导致在用户机器上
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-4512

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-4512

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-09-10 · 27 CVEs total

CVE-2007-4789Cisco内容交换模块远程拒绝服务漏洞
CVE-2007-4470Earth Resource Mapper NCSView ActiveX控件多个栈溢出漏洞
CVE-2007-3912debian-goodies Checkrestart Script 本地特权提升漏洞
CVE-2007-4799IBM AIX Perfstat Kernel Extension 本地拒绝服务漏洞
CVE-2007-4798IBM AIX Inventory Scout拒绝服务漏洞
CVE-2007-4797IBM AIX svprint Local 缓冲区溢出漏洞
CVE-2007-4796IBM AIX uucp Local 缓冲区溢出漏洞
CVE-2007-4795IBM AIX mkpath Local 缓冲区溢出漏洞
CVE-2007-4794IBM AIX fcstat Local 缓冲区溢出漏洞
CVE-2007-4793IBM AIX xlplm Local 缓冲区溢出漏洞
CVE-2007-4792IBM AIX ibstat Local 缓冲区溢出漏洞
CVE-2007-4791IBM AIX swcons Local 缓冲区溢出漏洞
CVE-2007-4790Microsoft Visual FoxPro 缓冲区错误漏洞
CVE-2007-4776Microsoft Visual Basic 6.0 VBP_Open函数缓冲区溢出漏洞
CVE-2007-4788Cisco内容交换模块远程拒绝服务漏洞
CVE-2007-4787Sophos Anti-Virus CAB、LZH和RAR文件绕过检测漏洞
CVE-2007-4786Cisco Adaptive Security Appliance 信任管理问题漏洞
CVE-2007-4785sony Micro Vault Fingerprint Access Software安装目录设置不当漏洞
CVE-2007-4784PHP本地参数拒绝服务漏洞
CVE-2007-4783PHP htmlentities和htmlspecialchars函数拒绝服务漏洞

Showing top 20 of 27 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-4512

No comments yet


Leave a comment