CVE-2014-7859
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Stack-based buffer overflow in login_mgr.cgi in D-Link firmware DNR-320L and DNS-320LW before 1.04b08, DNR-322L before 2.10 build 03, DNR-326 before 2.10 build 03, and DNS-327L before 1.04b01 allows remote attackers to execute arbitrary code by crafting malformed "Host" and "Referer" header values.
Un desbordamiento de búfer basado en pila en login_mgr.cgi en D-Link firmware DNR-320L y DNS-320LW en versiones anteriores a la 1.04b08, DNR-322L en versiones anteriores a la 2.10 build 03, DNR-326 en versiones anteriores a la 2.10 build 03, y DNS-327L en versiones anteriores a la 1.04b01 permite que atacantes remotos ejecuten código arbitrario mediante la manipulación de valores de cabecera "Host" y "Referer" con formato incorrecto.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-10-03 CVE Reserved
- 2015-05-28 CVE Published
- 2024-02-19 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/132075/D-Link-Bypass-Buffer-Overflow.html | Third Party Advisory | |
http://seclists.org/fulldisclosure/2015/May/125 | Mailing List | |
http://www.search-lab.hu/media/D-Link_Security_advisory_3_0_public.pdf | Technical Description | |
http://www.securityfocus.com/archive/1/535626/100/200/threaded | Mailing List | |
http://www.securityfocus.com/bid/74878 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
D-link Search vendor "D-link" | Dns-322l Firmware Search vendor "D-link" for product "Dns-322l Firmware" | <= 2.00b07 Search vendor "D-link" for product "Dns-322l Firmware" and version " <= 2.00b07" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dns-322l Search vendor "Dlink" for product "Dns-322l" | - | - |
Safe
|
D-link Search vendor "D-link" | Dns-320lw Firmware Search vendor "D-link" for product "Dns-320lw Firmware" | <= 1.03b04 Search vendor "D-link" for product "Dns-320lw Firmware" and version " <= 1.03b04" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dns-320lw Search vendor "Dlink" for product "Dns-320lw" | - | - |
Safe
|
D-link Search vendor "D-link" | Dnr-326 Firmware Search vendor "D-link" for product "Dnr-326 Firmware" | <= 1.40b03 Search vendor "D-link" for product "Dnr-326 Firmware" and version " <= 1.40b03" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dnr-326 Search vendor "Dlink" for product "Dnr-326" | - | - |
Safe
|
D-link Search vendor "D-link" | Dns-327l Firmware Search vendor "D-link" for product "Dns-327l Firmware" | <= 1.02 Search vendor "D-link" for product "Dns-327l Firmware" and version " <= 1.02" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dns-327l Search vendor "Dlink" for product "Dns-327l" | - | - |
Safe
|
D-link Search vendor "D-link" | Dnr-320l Firmware Search vendor "D-link" for product "Dnr-320l Firmware" | <= 1.03b04 Search vendor "D-link" for product "Dnr-320l Firmware" and version " <= 1.03b04" | - |
Affected
| in | Dlink Search vendor "Dlink" | Dnr-320l Search vendor "Dlink" for product "Dnr-320l" | - | - |
Safe
|