Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-1084

EPSS 10.43% · P93
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-1084

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP1, and Server 2008 allows local users to execute arbitrary code via unknown vectors related to improper input validation. NOTE: it was later reported that one affected function is NtUserFnOUTSTRING in win32k.sys.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Windows内核用户态回调本地权限提升漏洞(MS08-025)
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Windows是微软发布的非常流行的操作系统 。 Windows内核处理用户传入的数据时存在漏洞,本地攻击者可能利用此漏洞提升自己的权限 。 Windows内核没有正确验证从用户态传递到内核的输入,允许攻击者以提升的权限运行代码。成功利用此漏洞的攻击者可执行任意代码,并可完全控制受影响的系统。攻击者可随后安装程序;查看、更改或删除数据;或者创建拥有完全用户权限的新帐户 。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-1084

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-1084

登录查看更多情报信息。

Same Patch Batch · n/a · 2008-04-08 · 22 CVEs total

CVE-2008-1617Interwoven WorkSite Web TransferCtrl Class控件双重释放漏洞
CVE-2008-1699CMS 'permalink.php' SQL注入漏洞
CVE-2008-1698Simple_gallery gallery.php 跨站脚本攻击漏洞
CVE-2008-1697HP OpenView网络节点管理器OVAS.EXE远程栈溢出漏洞
CVE-2008-1696DaZPHPNews 'makepost.php' 目录遍历漏洞
CVE-2008-0313Symantec Norton SymAData.ActiveDataInfo.1 ActiveX 控件代码执行漏洞
CVE-2008-0312Symantec AutoFix支持工具SYMADATA.DLL控件多个安全漏洞
CVE-2008-1702e107 My_Gallery 插件 'dload.php' 路径遍历漏洞
CVE-2008-1701Novell NetWare 拒绝服务漏洞
CVE-2008-1700WorkSite Web 拒绝服务漏洞
CVE-2008-1686FishSound库 远程Speex 解码代码执行漏洞
CVE-2008-0083Microsoft VBScript和JScript脚本引擎远程溢出漏洞(MS08-022)
CVE-2008-0711HP iLO-2 Management Processors 拒绝服务漏洞
CVE-2008-1090Microsoft Visio Memory Validation 内存验证漏洞
CVE-2008-1089Microsoft Visio Object Header 未明漏洞
CVE-2008-1088Microsoft Project资源内存分配远程代码执行漏洞(MS08-018)
CVE-2008-1087Microsoft Windows GDI 'EMR_COLORMATCHTOTARGETW' 栈溢出漏洞
CVE-2008-1086Microsoft Internet Explorer 代码注入漏洞
CVE-2008-1085Microsoft Internet Explorer Data Stream Handling 远程代码执行漏洞
CVE-2008-1083Microsoft Windows GDI 'CreateDIBPatternBrushPt' Function 堆溢出漏洞

Showing top 20 of 22 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-1084

No comments yet


Leave a comment