Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2013-4636

EPSS 0.33% · P56
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2013-4636

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
PHP 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
PHP是一种在服务器端执行的脚本语言。 PHP 5.4.16之前的5.4.x版本中的Fileinfo组件中的libmagic/softmagic.c中的‘mget’函数中存在输入验证错误漏洞。远程攻击者可通过MP3文件在访问finfo对象期间触发不正确的MIME类型检测,利用该漏洞造成拒绝服务(无效指针引用和程序崩溃)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2013-4636

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2013-4636

登录查看更多情报信息。

Same Patch Batch · n/a · 2013-06-21 · 23 CVEs total

CVE-2013-0551IBM Application Manager for Smart Business/ITM 拒绝服务漏洞
CVE-2013-3379Cisco TelePresence TC软件权限许可和访问控制漏洞
CVE-2013-3378Cisco TelePresence TC/TE软件输入验证漏洞
CVE-2013-3377Cisco TelePresence TC/TE软件资源管理错误漏洞
CVE-2013-2173WordPress ‘crypt_private()’方法远程拒绝服务漏洞
CVE-2013-3035IBM AIX IPv6包处理远程拒绝服务漏洞
CVE-2013-0534IBM Sametime Connect客户端本地信息泄露漏洞
CVE-2013-0529IBM Sterling Connect:Direct 浏览器安全漏洞
CVE-2013-0527IBM Sterling Connect:Direct 浏览器安全漏洞
CVE-2013-2961IBM Application Manager for Smart Business/ITM 安全漏洞
CVE-2013-2960IBM Application Manager for Smart Business/ITM 缓冲区溢出漏洞
CVE-2013-3392Cisco WebEx Social 多个跨站请求伪造漏洞
CVE-2013-0548IBM Application Manager For Smart Business/ITM 多个跨站脚本漏洞
CVE-2013-0536IBM Notes Multi User Profile Cleanup Service 本地提权漏洞
CVE-2013-0523IBM WebSphere Commerce Enterprise 信息泄露漏洞
CVE-2012-6572Drupal 跨站脚本漏洞
CVE-2013-3250WordPress WP Maintenance Mode插件跨站请求伪造漏洞
CVE-2013-2110PHP 基于堆的缓冲区溢出漏洞
CVE-2013-4635PHP 数字错误漏洞
CVE-2013-4615多款Canon打印机存远程拒绝服务漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2013-4636

No comments yet


Leave a comment