Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-1935

EPSS 0.07% · P21
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-1935

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Integer overflow in the pipe_build_write_buffer function (sys/kern/sys_pipe.c) in the direct write optimization feature in the pipe implementation in FreeBSD 7.1 through 7.2 and 6.3 through 6.4 allows local users to bypass virtual-to-physical address lookups and read sensitive information in memory pages via unspecified vectors.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
FreeBSD直接管道写操作本地信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
FreeBSD就是一种运行在Intel平台上、可以自由使用的开放源码Unix类系统 。 FreeBSD和其他UNIX类系统上最常见的进程间通讯方式之一是匿名管道。这种机制会创建一对文件描述符,可以从一个描述符读取写入到另一个描述符的数据 。 FreeBSD的管道实现中包含名为"直接写入"的优化。在这种优化中,FreeBSD内核利用虚拟内存映射允许直接在进程之间拷贝数据,而不是在调用write(2)时将数据拷贝到内核内存,然后在调用read(2)时再次拷贝数据。在计算包含有所要拷贝数据的页面集时存在整数溢出
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-1935

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-1935

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-06-18 · 14 CVEs total

CVE-2009-2109FretsWeb 路径遍历漏洞
CVE-2009-2110jnmsolutions DB Top Sites 多个目录遍历漏洞
CVE-2009-2111jnmsolutions db_top_sites "add_reg.php" 代码注入漏洞
CVE-2009-2112frank-karau phpfk "page_bottom.php" 目录遍历漏洞
CVE-2009-2113FretsWeb SQL注入漏洞
CVE-2009-2114SkyBlueCanvas "admin.php" 多个跨站脚本攻击漏洞
CVE-2009-2115SkyBlueCanvas "admin.php" 信息泄露漏洞
CVE-2009-2116SkyBlueCanvas "admin.php" 目录遍历漏洞
CVE-2009-2117phportal "uye_paneli.php" 安全认证跳过和访问控制漏洞
CVE-2009-2118IrfanView TIFF文件处理整数溢出漏洞
CVE-2009-2119F5 Networks FirePass SSL VPN 登录界面未明跨站脚本攻击漏洞
CVE-2009-2120TekBase All-in-One 多个SQL注入漏洞
CVE-2009-2108Git "git-daemon" 远程拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2009-1935

No comments yet


Leave a comment