Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1110 CNY

100%

CVE-2013-0728

EPSS 7.14% · P92
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2013-0728

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple stack-based buffer overflows in NCSAddOn.dll in the ERDAS APOLLO ECWP plugin before 13.00.0001 for Internet Explorer, Firefox, and Chrome allow remote attackers to execute arbitrary code via a long property value.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
ERDAS APOLLO ECWP Browser插件‘NCSAddOn.dll’栈缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
ERDAS APOLLO ECWP Browser是美国Intergraph公司的一款浏览器插件。该插件提供Windows平台上的IE、Firefox、Chrome的ECWP支持。 ERDAS APOLLO ECWP Browser插件中存在基于栈的缓冲区溢出漏洞,该漏洞源于软件未正确对用户提供的输入进行边界值检查,导致程序复制数据的大小超出了分配的内存缓冲区空间。攻击者可利用该漏洞在受影响程序上下文中执行任意代码。也可导致拒绝服务。ERDAS APOLLO ECWP Browser Plugin 11.
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2013-0728

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-0728

登录查看更多情报信息。

Vendor Advisories for CVE-2013-0728 (1)

Same Patch Batch · n/a · 2013-04-25 · 28 CVEs total

CVE-2013-1215Cisco ASA Easy VPN组件权限获取漏洞
CVE-2013-1969libxml2 多个内存破坏漏洞
CVE-2013-1949WordPress Social Media Widget 插件HTML注入漏洞
CVE-2013-1948RubyGems ‘md2pdf’远程命令注入漏洞
CVE-2013-1947Ruby 操作系统命令注入漏洞
CVE-2013-1933Karteek Docsplit for Ruby ‘extract_from_ocr’函数任意命令执行漏洞
CVE-2013-1915ModSecurity XML External Entity 信息泄露漏洞
CVE-2013-0338Libxml2 Entity Expansion 拒绝服务漏洞
CVE-2013-0233Devise gem for Ruby 安全绕过漏洞
CVE-2013-0175Ruby multi_xml 远程任意命令执行漏洞
CVE-2012-4466Ruby ‘name_err_mesg_to_str API’函数安全绕过漏洞
CVE-2012-4464Ruby ‘exc_to_s’和‘name_err_to_s API’函数安全绕过漏洞
CVE-2013-2767Citrix NetScaler AGEE 未明安全漏洞
CVE-2013-2696WordPress All in One Webmaster插件跨站请求伪造漏洞
CVE-2013-3055Lexmark Markvision Enterprise 安全漏洞
CVE-2013-3269Cybozu Office 跨站请求伪造漏洞
CVE-2013-2305多款Cybozu产品跨站请求伪造漏洞
CVE-2013-1192Cisco Device Manager 多个远程命令执行漏洞
CVE-2013-1186Cisco Unified Computing System KVM 远程身份验证绕过漏洞
CVE-2013-1185Cisco Unified Computing System 远程信息泄露漏洞

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2013-0728

No comments yet


Leave a comment