- Description
- The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
- Source
- 3ff69d7a-14f2-4f67-a097-88dee7810d18
- NVD status
- Analyzed
- Products
- glibc, active_iq_unified_manager, debian_linux, hci_h300s_firmware, hci_h500s_firmware, hci_h700s_firmware, hci_h410s_firmware, hci_h410c_firmware, hci_h610c_firmware, hci_h610s_firmware, hci_h615c_firmware, hci_compute_node, ontap_select_deploy_administration_utility
CVSS 3.1
- Type
- Secondary
- Base score
- 7.3
- Impact score
- 4.7
- Exploitability score
- 2.5
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
- Severity
- HIGH
- 3ff69d7a-14f2-4f67-a097-88dee7810d18
- CWE-787
- Hype score
- Not currently trending
We found an interesting CTF-inspired vuln CVE-2026-22200 affecting osTicket, a popular ticketing system. It allows anonymous attackers to exfil local files as BMP images through the mPDF library. This can be chained to RCE if the host is vuln to CNEXT (CVE-2024-2961)
@Horizon3Attack
22 Jan 2026
5270 Impressions
17 Retweets
74 Likes
38 Bookmarks
2 Replies
0 Quotes
cve-2024-34102+CVE-2024-2961第一个漏洞已经解决,第二个漏洞libc和maps已经读取下来了,最后一部构造filterchain的时候一直有问题,没法rce,libc和maps可以保证是正确的。请问有大佬会的吗?
@Xiaoxiao_2585
18 Sept 2025
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 Cloudflare CIRCL (FourQ), Cryptographic Validation Flaw, #CVE-2024-2961 (Critical) https://t.co/4dcWIVX0UB
@dailycve
10 Jun 2025
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️Múltiples vulnerabilidades en HPE OneView ❗CVE-2024-38476 ❗CVE-2024-38475 ❗CVE-2024-38477 ❗CVE-2024-2961 ➡️Más info: https://t.co/f2jdGg96ol https://t.co/f6JFnAJ5Ze
@CERTpy
2 Jun 2025
141 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
Just rooted #BigBang (Hard) on #HTB (@hackthebox_eu) 🔓🔥 🕳️ WordPress LFI → CVE-2024-2961 → shell 🔄 DB creds → port-forward → SSH 🔐 Grafana hash → crack → user pivot 📲 APK reverse → subdomain → RCE → root 🎯 POC: https://t.co/t0CNJ0OJi2 #
@sakibulalikhan
1 May 2025
51 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gnu:glibc:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6CD7A500-A255-4B32-AA0B-A6D80A84406E",
"versionEndExcluding": "2.40",
"versionStartIncluding": "2.1.93",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*",
"matchCriteriaId": "3A756737-1CC4-42C2-A4DF-E1C893B4E2D5",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netapp:hci_h300s_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "4A19610F-99F4-4417-A1C9-B6E67644283C",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netapp:hci_h300s:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F0B3D528-2FDC-409C-9E2D-CD24C89260B8",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netapp:hci_h500s_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A62F5622-42A0-4515-908B-766C35F5D995",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netapp:hci_h500s:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0D62A5D9-F68D-4AAA-8EE7-A99A75C3AC0E",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netapp:hci_h700s_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "77CA07B4-6F60-4583-9005-814052140564",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netapp:hci_h700s:-:*:*:*:*:*:*:*",
"matchCriteriaId": "30796002-63B5-49DC-811A-CBB46E7057B1",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netapp:hci_h410s_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "75E26DD2-43C9-453C-A4BF-3E85771715E5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netapp:hci_h410s:-:*:*:*:*:*:*:*",
"matchCriteriaId": "4654B685-C68E-4FBA-9491-4EECA06D4E90",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netapp:hci_h410c_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "08C564D8-E21F-403C-B4BB-7B14B7FB5DAE",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netapp:hci_h410c:-:*:*:*:*:*:*:*",
"matchCriteriaId": "8532F5F0-00A1-4FA9-A80B-09E46D03F74F",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netapp:hci_h610c_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A9BC74D7-687D-46AA-862F-D755A3D1AA05",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netapp:hci_h610c:-:*:*:*:*:*:*:*",
"matchCriteriaId": "436851DF-1531-40CE-8C71-561978877E27",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netapp:hci_h610s_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "910D39ED-5E36-42F2-B824-E7F4A2ED0BD7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netapp:hci_h610s:-:*:*:*:*:*:*:*",
"matchCriteriaId": "33960CC8-DC73-4E15-8A19-686F5F528006",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netapp:hci_h615c_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "7AEAE936-CBDA-4C3A-B139-BE9C86EC6CB7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netapp:hci_h615c:-:*:*:*:*:*:*:*",
"matchCriteriaId": "D471C87E-D861-4AC7-9418-900858C5BF24",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:netapp:hci_compute_node:-:*:*:*:*:*:*:*",
"matchCriteriaId": "4AFE5CAF-ACA7-4F82-BEC1-69562D75E66E",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*",
"matchCriteriaId": "AD7447BC-F315-4298-A822-549942FC118B",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E7CF3019-975D-40BB-A8A4-894E62BD3797",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]