Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2007-6059

EPSS 0.94% · P76
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2007-6059

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Javamail does not properly handle a series of invalid login attempts in which the same e-mail address is entered as username and password, and the domain portion of this address yields a Java UnknownHostException error, which allows remote attackers to cause a denial of service (connection pool exhaustion) via a large number of requests, resulting in a SQLNestedException. NOTE: Sun disputes this issue, stating "The report makes references to source code and files that do not exist in the mentioned products.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Sun JavaMail SQLNestedException 拒绝服务攻击漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Javamail不能正确处理使用大量用户名和密码登录进同样的邮件地址的一系列非法登录尝试,会产生一个Java UnknownHostException 错误,这使得远程攻击者借助由一个SQLNestedException产生的大值请求造成拒绝服务。 注意:sun对此问题的翻译有纠纷,指出"报告书提到的源代码和文件,在提及的产品中不存在"。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2007-6059

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2007-6059

登录查看更多情报信息。

Same Patch Batch · n/a · 2007-11-20 · 45 CVEs total

CVE-2007-6051IBM DB2 UDB DB2ADMNS/DB2USERS 访问控制漏洞
CVE-2007-6054Aruba MC-800 Mobility Controller 管理界面登录页面跨站脚本攻击漏洞
CVE-2007-6053IBM DB2 UD 内存崩溃漏洞
CVE-2007-6055Novell Teaming用户枚举和跨站脚本漏洞
CVE-2007-6058ProfileCMS index.php多个参数 SQL注入漏洞
CVE-2007-6060AhnLab V3 ZIP文件解析内存破坏漏洞
CVE-2003-0857iptables中(1)ipq_read和(2) ipulog_read函数服务拒绝漏洞
CVE-2007-6061Audacity 后置链接漏洞
CVE-2007-6062ngIRCd irc-channel.c 拒绝服务漏洞
CVE-2007-6057Datecomm Social Networking Script index.php 远程文件包含漏洞
CVE-2007-6052IBM DB2 UDB 向量集合 拒绝服务攻击漏洞
CVE-2007-6050IBM DB2 UD DB2LICD 未明漏洞
CVE-2007-6049IBM DB2 UDB SSL LOAD GSKIT 未明漏洞
CVE-2007-6048IBM DB2 UDB DB2NODES.CFG 权限许可和访问控制漏洞
CVE-2007-6047IBM DB2 DB2DART工具 权限提升漏洞
CVE-2007-6046IBM DB2 UDB 未明setuid程序 未明漏洞
CVE-2007-6045IBM DB2 UDB DB2WATCH/DB2FREEZE 未明漏洞
CVE-2007-6044IBM WebSphere MQ 多个未明远程内存崩溃漏洞
CVE-2007-6043Microsoft Windows不安全随机数生成器信息泄露漏洞
CVE-2007-6042SWsoft Confixx Fehler.Inc.PHP 远程文件包含漏洞

Showing top 20 of 45 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2007-6059

No comments yet


Leave a comment