← volver
CVE-2015-0235

CVE-2015-0235

60Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendepss 95%
de la publicación al arma0 días
Publicada en NVD28 ene
1ª PoC27 ene
metasploit27 ene
probabilidad de explotación
95%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
24 exploit(s) público(s)
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
Productos afectados
n/a · n/a
PoCs públicas encontradas24 VexDay Proof
exploitdbVexDay Proofwww.exploit-db.com/exploits/36421exploitdbwww.exploit-db.com/exploits/35951no verificadogithubgithub.com/aaronfay/CVE-2015-0235-test15githubgithub.com/fser/ghost-checker6githubgithub.com/makelinux/CVE-2015-0235-workaround6githubgithub.com/arm13/ghost_exploit4githubgithub.com/mikesplain/CVE-2015-0235-cookbook3githubgithub.com/nickanderson/cfengine-CVE_2015_02351githubgithub.com/furyutei/CVE-2015-0235_GHOST1githubgithub.com/adherzog/ansible-CVE-2015-0235-GHOST1githubgithub.com/alanmeyer/CVE-glibc0githubgithub.com/1and1-serversupport/ghosttester0githubgithub.com/sUbc0ol/CVE-2015-02350githubgithub.com/chayim/GHOSTCHECK-cve-2015-02350githubgithub.com/F88/ghostbusters150githubgithub.com/tobyzxj/CVE-2015-02350githubgithub.com/favoretti/lenny-libc60githubgithub.com/koudaiii-archives/cookbook-update-glibc0cve_referencepacketstormsecurity.com/files/130974/Exim-GHOST-glibc-gethostbyname-Buffer-Overflow.htmlno verificadocve_referencepacketstormsecurity.com/files/130171/Exim-ESMTP-GHOST-Denial-Of-Service.htmlno verificadocve_referencepacketstormsecurity.com/files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.htmlno verificadocve_referencepacketstormsecurity.com/files/153278/WAGO-852-Industrial-Managed-Switch-Series-Code-Execution-Hardcoded-Credentials.htmlno verificadocve_referencepacketstormsecurity.com/files/167552/Nexans-FTTO-GigaSwitch-Outdated-Components-Hardcoded-Backdoor.htmlno verificadocve_referencepacketstormsecurity.com/files/130768/EMC-Secure-Remote-Services-GHOST-SQL-Injection-Command-Injection.htmlno verificado
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.