Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-2541

EPSS 19.96% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-2541

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple stack-based buffer overflows in the HTTP Gateway Service (icihttp.exe) in CA eTrust Secure Content Manager 8.0 allow remote attackers to execute arbitrary code or cause a denial of service via long FTP responses, related to (1) the file month field in a LIST command; (2) the PASV command; and (3) directories, files, and links in a LIST command.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
CA eTrust Secure Content Manager HTTP网关服务 多个栈溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
eTrust Secure Content Manager(eTrust SCM)是独立、统一的网关解决方案,能够帮助企业从中央管理控制台防范资料窃密以及网络和信息传递威胁。 eTrust SCM运行在8080端口上的HTTP网关服务(icihttp.exe)中存在多个栈溢出漏洞。如果用户发布了FTP服务请求,进程会试图修饰事件处理的内容,在这种情况下如果指定了超长的LIST或PASV命令响应,就会触发栈溢出,导致以SYSTEM权限执行任意指令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-2541

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-2541

登录查看更多情报信息。

Same Patch Batch · n/a · 2008-06-04 · 31 CVEs total

CVE-2008-1108Evolution 时区附件数据解析方式缓冲区溢出漏洞
CVE-2008-2549Adobe Reader 畸形PDF文档未明远程拒绝服务漏洞
CVE-2008-2548Motorola RAZR EXIF解析器 JPEG thumbprint组件缓冲区溢出漏洞
CVE-2008-2547Microsoft Windows_installer msiexec.exe 缓冲区溢出漏洞
CVE-2008-2119Asterisk SIP通道驱动远程拒绝服务漏洞
CVE-2008-1947Apache Tomcat 跨站脚本漏洞
CVE-2008-1661HP StorageWorks存储镜像软件远程栈溢出漏洞
CVE-2008-2550ibm websphere_application_server 网站服务安全组件未明漏洞
CVE-2008-2406Sun Java ASP服务器 管理应用服务认证绕过漏洞
CVE-2008-2405Sun Java ASP服务器 ASP应用输入任意命令执行漏洞
CVE-2008-2404Sun Java ASP服务器implementation 栈溢出漏洞
CVE-2008-2403Sun Java ASP服务器 HTTP请求目录遍历漏洞
CVE-2008-2402Sun Java ASP服务器 根目录数据信息泄露漏洞
CVE-2008-2401Sun Java ASP服务器 ASP应用捆绑文件输入验证漏洞
CVE-2008-1109Gnome Evolution iCalendar附件解析多个缓冲区溢出漏洞
CVE-2008-2551Icona SpA C6 Messenger Installation URL Downloader ActiveX控件输入验证漏洞
CVE-2008-0953HP Instant Support HPISDataManager.dll ActiveX控件 StartApp 功能缓冲区溢出漏洞
CVE-2008-0952HP Instant Support HPISDataManager.dll ActiveX控件 AppendStringToFile 功能文件创建漏洞
CVE-2007-5610HP Instant Support HPISDataManager.dll ActiveX控件 DeleteSingleFile功能任意文件删除漏洞
CVE-2007-5608HP Instant Support HPISDataManager.dll ActiveX控件 DownloadFile功能任意文件下载漏洞

Showing top 20 of 31 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2008-2541

No comments yet


Leave a comment