本文是对此博客二进制场景下的所有CVE(共计36个)复现笔记的汇总,权供学习参考。
未有引用的CVE代表笔记暂时还未完成,笔者闲暇时也许会补上(),如果有想法想交流或者想纠正笔误,欢迎发信至ch0ser@std.uestc.edu.cn或choser@qq.com。
以及申明:以下工作都是A.S.E (AI Code Generation Security Evaluation)开源项目的一部分;
笔者是这部分工作的contributor,很荣幸能够参与该开源项目,为大模型的安全评估做出贡献。
openjpeg(9)
- openjpeg_01: CVE-2017-14164
- openjpeg_02: CVE-2016-7445
- openjpeg_03: CVE-2016-9118
- openjpeg_04: CVE-2016-10504
- openjpeg_05: CVE-2018-5785
- openjpeg_06: CVE-2018-6616
- openjpeg_07: CVE-2018-5727
- openjpeg_08: CVE-2018-18088
- openjpeg_09: CVE-2020-27814
libjpeg(8)
- libjpeg_01: CVE-2020-13790
- libjpeg_02: CVE-2018-14498
- libjpeg_03:CVE-2018-20330
- libjpeg_04:CVE-2018-19664
- libjpeg_05:CVE-2018-11813
- libjpeg_06:CVE-2019-2201
- libjpeg_07:CVE-2021-37972
- libjpeg_08:CVE-2021-20205
libxml2(4)
- libxml2_01:CVE-2017-5969
- libxml2_02:CVE-2017-9047
- libxml2_03:CVE-2017-9048
- libxml2_04:CVE-2018-9251
binutils (1)
- binutils_01:CVE-2017-7303
lrzip(1)
- lrzip_01:CVE-2018-5786
gpac(10)
- gpac_01:CVE-2024-0321
- gpac_02:CVE-2023-4756
- gpac_03:CVE-2023-4754
- gpac_04:CVE-2023-0770
- gpac_05:CVE-2021-29279
- gpac_06:CVE-2020-24829
- gpac_07:CVE-2020-23267
- gpac_08:CVE-2020-23266
- gpac_09:CVE-2019-20208
- gpac_10:CVE-2019-20162
ImageMagick(1)
- ImageMagick_01:CVE-2020-10251
libexpat(2)
- libexpat_01:CVE-2024-28757
- libexpat_02:CVE-2019-15903