Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-0036

EPSS 10.34% · P93
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2012-0036

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
cURL/libcURL SQL注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
cURL是命令行传输文件工具,支持FTP、FTPS、HTTP、HTTPS、GOPHER、TELNET、DICT、FILE和LDAP。 cURL/libcURL 7.20.0至7.23.1版本中存在输入验证漏洞,攻击者可利用该漏洞向基于libcURL的应用程序中注入任意数据。该漏洞影响下列协议:IMAP、POP3和 SMTP。攻击成功将允许攻击者执行未授权操作,例如欺骗POP3客户端删除信息,或SMTP服务器发送意外信息,也可能执行其它攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2012-0036

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-0036

Please Login to view more intelligence information

Same Patch Batch · n/a · 2012-04-13 · 15 CVEs total

CVE-2010-4666libarchive 缓冲区溢出漏洞
CVE-2011-1777Red Hat libarchive缓冲区溢出漏洞
CVE-2011-1778Red Hat libarchive缓冲区溢出漏洞
CVE-2011-1779libarchive 资源管理错误漏洞
CVE-2012-1805Koyo多个产品‘ECOM Etherne’模块缓冲区溢出漏洞
CVE-2012-1806Koyo多个产品‘ECOM Ethernet’模块授权问题漏洞
CVE-2012-1807Koyo 多个产品‘ECOM100 Ethernet ’模块跨跨脚本漏洞
CVE-2012-1808Koyo多个产品‘ECOM Ethernet’模块授权问题漏洞
CVE-2012-1809Koyo多个产品‘ECOM Ethernet’模块资源管理错误漏洞
CVE-2011-4874MICROSYS PROMOTIC 资源管理错误漏洞
CVE-2011-4880atvise webMI2ADS多个安全漏洞
CVE-2011-4881Certec atvise webMI2ADS多个安全漏洞
CVE-2011-4882Certec atvise webMI2ADS多个安全漏洞
CVE-2011-4883Certec atvise webMI2ADS多个安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2012-0036

No comments yet


Leave a comment