Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-0318

EPSS 0.03% · P10
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-0318

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777 permissions instead of the original permissions, which might allow local users to read or modify unauthorized files in opportunistic circumstances after a system crash or power failure.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
FreeBSD ZFS Intent Log非安全文件许可漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
当在setattr交易的重放过程中建立文件时,FreeBSD 7.1,7.2,以及8.0版本中的ZFS Intent Log (ZIL)的重放功能使用一个较弱的许可(7777许可)代替原许可。本地用户可在系统崩溃或断电后读取或修改未授权文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-0318

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-0318

登录查看更多情报信息。

Same Patch Batch · n/a · 2010-01-15 · 37 CVEs total

CVE-2010-0344TYPO3 zak_store_management extension SQL注入漏洞
CVE-2010-0336TYPO3 kiddog_mysqldumper extension未明漏洞
CVE-2010-0337TYPO3 tt_news Mail alert extensionSQL注入漏洞
CVE-2010-0338TYPO3 TT_Products editor (ttpedit) extensionSQL注入漏洞
CVE-2010-0339TYPO3 User Links (vm19_userlinks) extension SQL注入漏洞
CVE-2010-0340TYPO3 MJS Event Pro (mjseventpro) extension SQL注入漏洞
CVE-2010-0341TYPO3 BB Simple Jobs (bb_simplejobs) extensionSQL注入漏洞
CVE-2010-0342TYPO3 Reports for Job (job_reports) extension SQL注入漏洞
CVE-2010-0343TYPO3 Clan Users List (pb_clanlist) extension SQL注入漏洞
CVE-2010-0335TYPO3 news extension Vote rank跨站脚本漏洞
CVE-2010-0345TYPO3 Majordomo extension 跨站脚本漏洞
CVE-2010-0346TYPO3 Tip many friends extension 跨站脚本漏洞
CVE-2010-0347TYPO3 VD / Geomap (vd_geomap) extension 跨站脚本漏洞
CVE-2010-0348C3 Corp. WebCalenderC3 目录遍历漏洞
CVE-2010-0317Novell Netware 大量畸形或AFP请求引起一个拒绝服务
CVE-2010-0249Microsoft Internet Explorer非法事件操作内存破坏漏洞
CVE-2010-0280Google SketchUp lib3ds库3DS文件处理内存破坏漏洞
CVE-2010-0316Google Sketchup整数溢出漏洞
CVE-2010-0326TYPO3 Developer log (devlog) extension 跨站脚本漏洞
CVE-2010-0350TYPO3 Photo Book extension 目录遍历漏洞

Showing top 20 of 37 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-0318

No comments yet


Leave a comment