Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-2939

EPSS 10.27% · P93
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-2939

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted private key with an invalid prime. NOTE: some sources refer to this as a use-after-free issue.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OpenSSL 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenSSL是OpenSSL团队的一个开源的能够实现安全套接层(SSLv2/v3)和安全传输层(TLSv1)协议的通用加密库。该产品支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。 OpenSSL 1.0.0a,0.9.8,0.9.7版本存在资源管理错误漏洞,当ECDH启用时,附近攻击者可以借助特制的无效质数私钥导致拒绝服务(崩溃)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-2939

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-2939

Please Login to view more intelligence information

Same Patch Batch · n/a · 2010-08-17 · 17 CVEs total

CVE-2009-3737Oracle Siebel Option Pack代码注入漏洞
CVE-2010-0126Autonomy KeyView缓冲区溢出漏洞
CVE-2010-0131Autonomy KeyView 'wkssr.dll'缓冲区溢出漏洞
CVE-2010-0133Autonomy KeyView 'wkssr.dll'缓冲区溢出漏洞
CVE-2010-0134Autonomy KeyView 'rtfsr.dll'数字错误漏洞
CVE-2010-0135Autonomy KeyView 'wosr.dll'缓冲区溢出漏洞
CVE-2010-1524Autonomy KeyView 'wkssr.dll'缓冲区溢出漏洞
CVE-2010-1525Autonomy KeyView 'wkssr.dll'数字错误漏洞
CVE-2010-1870Apache Atlassian Fisheye Struts Xwork设计错误漏洞
CVE-2010-2241Red Hat目录服务器'setup-ds.pl'和'setup-ds-admin.pl'权限许可和访问控制漏洞
CVE-2010-3030Tomaz Muraus Open Blog跨站请求伪造漏洞
CVE-2010-3031Wyse ThinOS HF缓冲区溢出漏洞
CVE-2010-3032SAP Crystal Reports 'ebus-3-3-2-6.dll'模块数字错误漏洞
CVE-2010-1516SWFTools 'lib/png.c'和'lib/jpeg.c'数字错误漏洞
CVE-2010-2812ZNC 'Client.cpp'输入验证漏洞
CVE-2010-2934ZNC 多个未明漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2010-2939

No comments yet


Leave a comment