Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2016-3947

EPSS 75.37% · P99
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2016-3947

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Squid pinger 基于堆的缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Squid(全称Squid Cache)是一套代理服务器和Web缓存服务器软件,它提供缓存万维网、过滤流量、代理上网等功能。pinger是其中的一个用于指定ping进程完整路径的进程。 Squid 3.5.16之前版本和4.0.8之前4.x版本的pinger中的icmp/Icmp6.cc文件中的‘Icmp6::Recv’函数存在基于堆的缓冲区溢出漏洞。远程攻击者可通过发送特制的ICMPv6数据包利用该漏洞造成拒绝服务(性能退化或转换失败),或向日志文件中写入敏感信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2016-3947

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2016-3947

登录查看更多情报信息。

Same Patch Batch · n/a · 2016-04-07 · 36 CVEs total

CVE-2016-0791CloudBees Jenkins CI和LTS 安全漏洞
CVE-2015-2774Erlang OTP 信息泄露漏洞
CVE-2016-0729Apache Xerces XML Parser库缓冲区错误漏洞
CVE-2016-2086Joyent Node.js 安全漏洞
CVE-2016-2216Joyent Node.js HTTP响应拆分攻击
CVE-2016-2511websvn 跨站脚本漏洞
CVE-2016-0788CloudBees Jenkins CI和LTS 远程代码执行漏洞
CVE-2016-0789CloudBees Jenkins CI和LTS CLI CRLF注入漏洞
CVE-2016-0790CloudBees Jenkins CI和LTS 安全漏洞
CVE-2016-2510BeanShell 任意命令执行漏洞
CVE-2016-0792CloudBees Jenkins CI和LTS 任意代码执行漏洞
CVE-2016-1531Exim Configuration File Path 安全漏洞
CVE-2016-2097Ruby on Rails Action View组件目录遍历漏洞
CVE-2016-2098Ruby on Rails Action Pack 安全漏洞
CVE-2016-2563PuTTY和KiTTY 基于栈的缓冲区溢出漏洞
CVE-2016-2789Citrix Systems XenMobile Server 跨站脚本漏洞
CVE-2016-2851libotr 整数溢出漏洞
CVE-2016-3976SAP NetWeaver AS Java 目录遍历漏洞
CVE-2016-3974SAP NetWeaver AS Java Configuration Wizard XML外部实体漏洞
CVE-2016-1019Adobe Flash Player 安全漏洞

Showing top 20 of 36 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2016-3947

No comments yet


Leave a comment