Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2013-3480

EPSS 8.43% · P92
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2013-3480

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Integer overflow in Sagelight 4.4 and earlier allows remote attackers to execute arbitrary code via crafted width and height dimensions in a BMP file, which triggers a heap-based buffer overflow.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Sagelight BMP文件处理远程堆缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Sagelight是美国19th Parallell公司的一款图片编辑器产品。该产品具有功能全面、设计精美的特点。 Sagelight中存在基于堆的缓冲区溢出漏洞,该漏洞源于程序没有对用户提交的数据执行边界值检查。远程攻击者可利用该漏洞在用户运行的应用程序上下文中执行任意代码,也可造成拒绝服务。Sagelight 4.4版本中存在漏洞,其他版本也可能受到影响。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2013-3480

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-3480

登录查看更多情报信息。

Same Patch Batch · n/a · 2013-08-09 · 34 CVEs total

CVE-2013-0492IBM Informix Open Admin Tool 跨站脚本漏洞
CVE-2013-4759Magnolia CMS 多个跨站脚本漏洞
CVE-2013-4789Cotonti ‘c’参数SQL注入漏洞
CVE-2013-5098WordPress Download Monitor插件跨站脚本漏洞
CVE-2013-5099Anchor CMS ‘name’ Field HTML注入漏洞
CVE-2012-6458SilverStripe e-commerce模块多个跨站脚本漏洞
CVE-2013-4115Squid ‘idnsALookup()’函数远程缓冲区溢出漏洞
CVE-2013-5100TYPO3 Static Methods since 2007 Extension 未明跨站脚本漏洞
CVE-2012-3039多款MOXA OnCell Gateways产品未充分加密漏洞
CVE-2013-4742SurgeFTP 远程缓冲区溢出漏洞
CVE-2013-0494IBM Sterling B2B Integrator 拒绝服务漏洞
CVE-2013-2792Schweitzer Engineering Laboratories 多款设备远程拒绝服务漏洞
CVE-2013-2796Schneider Electric Vijeo Citect/CitectSCADA/PowerLogic SCADA XML外部实体注入漏洞
CVE-2013-2798Schweitzer Engineering Laboratories 多款设备本地拒绝服务漏洞
CVE-2013-4031IBM IMM和IMM2模块IPMI实现安全漏洞
CVE-2013-4037IBM IMM和IMM2模块IPMI实现安全漏洞
CVE-2013-4038IBM Integrated Management Module IPMI实现安全漏洞
CVE-2013-0150F5 BIG-IP APM/FirePass Java小应用程序目录遍历漏洞
CVE-2013-4625WordPress Duplicator插件跨站脚本漏洞
CVE-2013-4620OpenEMR ‘note’参数跨站脚本漏洞

Showing top 20 of 34 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2013-3480

No comments yet


Leave a comment