Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2016-6814

EPSS 24.32% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2016-6814

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an attacker to bake a special serialized object that will execute code directly when deserialized. All applications which rely on serialization and do not isolate the code which deserializes objects were subject to this vulnerability.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache Groovy 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Groovy是美国阿帕奇(Apache)软件基金会的一种基于Java平台面向对象的编程语言,它结合了Python、Ruby和Smalltalk的许多强大的特性。 Apache Groovy 2.4.4版本至2.4.7版本和1.7.0版本至2.4.3版本中存在远程代码执行漏洞。攻击者可通过制作序列化对象利用该漏洞在用户运行的受影响应用程序上下文中执行任意代码,造成拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2016-6814

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2016-6814

登录查看更多情报信息。

Same Patch Batch · n/a · 2018-01-18 · 44 CVEs total

CVE-2018-5766Libav 安全漏洞
CVE-2017-15869LiveZilla 跨站脚本漏洞
CVE-2014-2017OXID eShop 安全漏洞
CVE-2017-12729Moxa SoftCMS Live Viewer SQL注入漏洞
CVE-2017-17860Samsung Gear S2和S3 输入验证错误漏洞
CVE-2018-5776WordPress MediaElement 跨站脚本漏洞
CVE-2012-6708jQuery 跨站脚本漏洞
CVE-2015-9251jQuery 跨站脚本漏洞
CVE-2016-10707jQuery 安全漏洞
CVE-2018-5773markdown2 跨站脚本漏洞
CVE-2018-5772Exiv2 安全漏洞
CVE-2018-0115Cisco ASR 5000 Series路由器Cisco StarOS操作系统命令注入漏洞
CVE-2018-0111Cisco WebEx Meetings Server 信息泄露漏洞
CVE-2018-0110Cisco WebEx Meetings Server 安全漏洞
CVE-2018-0109Cisco WebEx Meetings Server 信息泄露漏洞
CVE-2018-0108Cisco WebEx Meetings Server 信息泄露漏洞
CVE-2018-0107Cisco Prime Service Catalog 跨站脚本漏洞
CVE-2018-0106Cisco Elastic Services Controller 信息泄露漏洞
CVE-2018-0105Cisco Unified Communications Manager 信息泄露漏洞
CVE-2018-0102Cisco Nexus 7000 Series Switches和7700 Series Switches Cisco NX-OS Software 安全漏洞

Showing top 20 of 44 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2016-6814

No comments yet


Leave a comment