Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-18019

EPSS 1.43% · P81
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2017-18019

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which in turn can be used to read the contents of arbitrary memory. Similarly, the product crashes upon a \\.\K7Sentry DeviceIoControl call with an invalid kernel pointer.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
K7 Total Security 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
K7 Total Security是印度K7 Computing公司的一款网络安全防护设备。 K7 Total Security 15.1.0.305之前的版本中存在安全漏洞,该漏洞源于程序没有充分的过滤用户的输入。攻击者可利用该漏洞读取任意内存内容。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2017-18019

#POC DescriptionSource LinkShenlong Link
1Under Construction :) Please come back laterhttps://github.com/SpiralBL0CK/CVE-2017-18019POC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2017-18019

登录查看更多情报信息。

Same Patch Batch · n/a · 2018-01-04 · 21 CVEs total

CVE-2018-5212WordPress Simple Download Monitor插件跨站脚本漏洞
CVE-2018-5220K7 Antivirus K7Sentry.sys 安全漏洞
CVE-2018-5219K7 Antivirus K7FWHlpr.sys文件安全漏洞
CVE-2018-5218K7 Antivirus K7Sentry.sys 安全漏洞
CVE-2018-5217K7 Antivirus K7Sentry.sys 安全漏洞
CVE-2018-5216Radiant CMS 跨站脚本漏洞
CVE-2018-5215Fork CMS 跨站脚本漏洞
CVE-2017-17867Inteno iopsys 安全漏洞
CVE-2018-5214WordPress Add Link to Facebook插件跨站脚本漏洞
CVE-2018-5213WordPress Simple Download Monitor插件跨站脚本漏洞
CVE-2017-18018GNU Coreutils 安全漏洞
CVE-2017-14960OpenText Document Sciences xPression xDashboard SQL注入漏洞
CVE-2014-7862ZOHO ManageEngine Desktop Central和Desktop Central MSP 权限许可和访问控制漏洞
CVE-2018-5210Samsung移动设备缓冲区错误漏洞
CVE-2018-1190Pivotal Cloud Foundry Runtime cf-release、UAA和UAA bosh 跨站脚本漏洞
CVE-2018-0114Cisco node-jose open source library 数据伪造问题漏洞
CVE-2018-0104多款Cisco产品WebEx ARF player 安全漏洞
CVE-2018-0103多款Cisco产品WebEx ARF player 缓冲区错误漏洞
CVE-2017-18020Samsung移动设备安全漏洞
CVE-2017-14383Dell EMC VNX2 Operating Environment for File和VNX1 Operating Environment for File VNX Contr

IV. Related Vulnerabilities

V. Comments for CVE-2017-18019

No comments yet


Leave a comment