Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-0738

EPSS 0.99% · P77
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-0738

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server, which allows remote attackers to spoof the server and conduct man-in-the-middle (MITM) attacks via a crafted certificate when executing (a) myproxy-logon or (b) myproxy-get-delegation.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Globus MyProxy证书验证安全绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
MyProxy 是一个网络浏览辅助软件。 在Globus Toolkit 5.0.0至5.0.2版本中使用的MyProxy 5.0至5.2版本没有正确验证发布给myproxy-server的X.509证书中的(1)hostname或者(2)identity。远程攻击者可以在执行(a)myproxy-logon或者(b)myproxy-get-delegation时,借助特制证书欺骗服务器并进行中间人(MITM)攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-0738

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-0738

登录查看更多情报信息。

Same Patch Batch · n/a · 2011-02-02 · 25 CVEs total

CVE-2010-3719Symantec IM Manager IMAdminSchedTask.asp文件eval注入漏洞
CVE-2011-0742Novell ZENworks Handheld Management ZfHIPCnd.exe缓冲区溢出漏洞
CVE-2011-0741MODx Evolution多个跨站脚本攻击漏洞
CVE-2011-0740Pleer RSS Feed Reader magpie/scripts/magpie_slashbox.php跨站脚本攻击漏洞
CVE-2011-0739Ruby Mail gem deliver功能任意Shell命令执行漏洞
CVE-2011-0276HP OpenView Performance Insight Server远程任意代码执行漏洞
CVE-2011-0017Exim 'log.c'程序本地权限提升漏洞
CVE-2010-4652ProFTPD mod_sql模块远程堆缓冲区溢出漏洞
CVE-2010-4015PostgreSQL intarray数组模块gettoken()函数缓冲区溢出漏洞
CVE-2010-3930MODx Evolution目录遍历漏洞
CVE-2010-3929MODx Evolution AjaxSearch SQL注入漏洞
CVE-2010-3854Apache CouchDB Web管理界面多个跨站脚本攻击漏洞
CVE-2010-3041Cisco WebEx WRF和ARF文件格式处理多个缓冲区溢出漏洞
CVE-2011-0755PHP mt_rand函数整数溢出漏洞
CVE-2011-0754PHP Standard PHP Library扩展SplFileInfo::getType函数后置链接漏洞
CVE-2011-0753PHP PCNTL扩展拒绝服务漏洞
CVE-2011-0752PHP extract功能输入验证漏洞
CVE-2011-0757IBM DB2 DBADM权限撤销非DDL声明执行漏洞
CVE-2011-0521Linux Kernel 'dvb_ca_ioctl()'内存破坏漏洞
CVE-2010-3270Cisco WebEx ATP文件栈缓冲区溢出漏洞

Showing top 20 of 25 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2011-0738

No comments yet


Leave a comment