Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2010-3444

EPSS 3.12% · P87
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2010-3444

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Buffer overflow in the log2vis_utf8 function in pyfribidi.c in GNU FriBidi 0.19.1, 0.19.2, and possibly other versions, as used in PyFriBidi 0.10.1, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted Arabic UTF-8 string that causes original 2-byte UTF-8 sequences to be transformed into 3-byte sequences.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Fribidi Fedora pyfribidi任意代码执行漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GNU FriBidi 是一个统一码双向文稿算法的自由实作。 用于PyFriBidi 0.10.1版本的GNU FriBidi 0.19.1、0.19.2也可能是其他版本中的pyfribidi.c文件中的log2vis_utf8函数中存在缓冲区溢出漏洞。远程攻击者可以借助特制Arabic UTF-8字符串(该字符串导致原始2字节UTF-8序列转换为3字节序列)导致拒绝服务(崩溃)以及可能执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2010-3444

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-3444

Please Login to view more intelligence information

Same Patch Batch · n/a · 2011-01-11 · 28 CVEs total

CVE-2010-4247Linux kernel 输入验证错误漏洞
CVE-2011-0407Phenotype CMS存储功能SQL注入漏洞
CVE-2011-0406WellinTech KingView 'HistorySvr.exe'堆缓冲区溢出漏洞
CVE-2011-0405PhpGedView module.php文件目录遍历漏洞
CVE-2011-0404NetSupport Manager Agent栈缓冲区溢出漏洞
CVE-2011-0403ImgBurn ImgBurn.exe文件不可信搜索路径漏洞
CVE-2011-0402Debian dpkg dpkg-source任意文件修改漏洞
CVE-2011-0007Troglobit pimd任意文件覆盖漏洞
CVE-2011-0005Joomla! com_search模块跨站脚本攻击漏洞
CVE-2011-0003MediaWiki输入验证漏洞
CVE-2010-4693Coppermine Photo Gallery多个跨站脚本攻击漏洞
CVE-2010-4645PHP zend_strtod函数畸形浮点值数字错误漏洞
CVE-2010-4526Linux kernel 竞争条件问题漏洞
CVE-2010-4525Linux Kernel敏感信息泄露漏洞
CVE-2010-3676MySQL mysqld DDL声明拒绝服务漏洞
CVE-2010-4242Linux Kernel HCI UART驱动hci_uart_tty_open函数本地拒绝服务漏洞
CVE-2010-4225Mono ASP.NET源代码信息泄露漏洞
CVE-2010-4175Linux Kernel rds_cmsg_rdma_args函数拒绝服务和内存破坏漏洞
CVE-2010-3865Linux kernel 输入验证错误漏洞
CVE-2010-1679Ubuntu dpkg数据操作和系统攻击漏洞

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-3444

No comments yet


Leave a comment