Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-4642

EPSS 29.88% · P97
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-4642

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple buffer overflows in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allow remote attackers to execute arbitrary code via a long chat (PKT_CHAT) message that is not properly handled by the (1) D_NetPlayerEvent function in d_net.c or the (2) Msg_Write function in net_msg.c, or (3) many commands that are not properly handled by the NetSv_ReadCommands function in d_netsv.c; or (4) cause a denial of service (daemon crash) via a chat (PKT_CHAT) message without a final '\0' character.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Doomsday Engine 多个远程漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Doomsday (又称deng) 1.9.0-beta5.1版本及其早期版本中存在多个缓冲区溢出。 远程攻击者可以借助一个超长的在(1) d_net.c的D_NetPlayerEvent函数或 (2) net_msg.c中的Msg_Write函数中未经过适当处理的chat (PKT_CHAT)信息,或(3)d_netsv.c的NetSv_ReadCommands函数中学多未经过适当处理的指令,执行任意代码; 或(4)可以借助不具备一个最终 '\0'字符的chat (PKT_CHAT)信息,造成拒绝服务(
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-4642

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-4642

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-08-31 · 47 CVEs total

CVE-2007-4606PHPNuke-Clan PHPNuke-Clan PHPNuke-Clan 代码注入漏洞
CVE-2007-4609EyeOS Project EyeOS Unknown 权限许可和访问控制漏洞
CVE-2007-4611Dale Mooney Calendar Events Viewevent.PHP SQL注入漏洞
CVE-2007-4614BEA产品多个远程安全漏洞
CVE-2007-4615BEA WebLogic Server SSL客户应用程序会话劫持漏洞
CVE-2007-4616BEA WebLogic Server SSL服务器密码设置漏洞
CVE-2007-4617BEA WebLogic Server 未明漏洞
CVE-2007-4618BEA产品多个远程安全漏洞
CVE-2007-4613BEA产品多个远程安全漏洞
CVE-2007-4607EasyMail Objects EMSMTP.DLL ActiveX控件 远程缓冲区溢出漏洞
CVE-2007-4608Winterburns.co.uk EPersonnel RC_2004_02 代码注入漏洞
CVE-2007-4605VWar Virtual War 代码注入漏洞
CVE-2007-4604DL PayCart 'viewitem.php'SQL注入漏洞
CVE-2007-4603ACG News 'index.php' 多个SQL注入漏洞
CVE-2007-4602Implied Implied By Design Micro CMS SQL注入漏洞
CVE-2007-4467Oracle JInitiator ActiveX控件 多个缓冲区溢出漏洞
CVE-2007-4630Absolute Poll Manager XE'xlaapmview.asp'跨站脚本攻击漏洞
CVE-2007-4629MapServer 'maptemplate.c'远程栈溢出漏洞
CVE-2007-4628phpns 'shownews.php' SQL注入漏洞
CVE-2007-4627ABC eStore 'index.php' SQL注入漏洞

Showing top 20 of 47 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-4642

No comments yet


Leave a comment