CVE-2024-2961
HIGH EXPLOITED NUCLEIGNU C Library <2.39 - Buffer Overflow
Title source: llmDescription
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
Exploits (16)
nomisec
WORKING POC
5 stars
by kyotozx · infoleak
https://github.com/kyotozx/CVE-2024-2961-Remote-File-Read
nomisec
WORKING POC
4 stars
by suce0155 · remote
https://github.com/suce0155/CVE-2024-2961_buddyforms_2.7.7
nomisec
WORKING POC
1 stars
by omarelshopky · remote
https://github.com/omarelshopky/exploit_cve-2023-26326_using_cve-2024-2961
metasploit
WORKING POC
EXCELLENT
by Sergey Temnikov, Charles Fol, Heyder, jheysel-r7 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/magento_xxe_to_glibc_buf_overflow.rb
Nuclei Templates (1)
PHP - LFR to Remote Code Execution
HIGHby Kim Dongyoung (Kairos-hk),bolkv,n0ming,RoughBoy0723
References (19)
Scores
CVSS v3
7.3
EPSS
0.9192
EPSS Percentile
99.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Details
VulnCheck KEV
2024-09-16
CWE
CWE-787
Status
published
Products (14)
debian/debian_linux
10.0
gnu/glibc
2.1.93 - 2.40
netapp/active_iq_unified_manager
netapp/hci_compute_node
netapp/hci_h300s_firmware
netapp/hci_h410c_firmware
netapp/hci_h410s_firmware
netapp/hci_h500s_firmware
netapp/hci_h610c_firmware
netapp/hci_h610s_firmware
... and 4 more
Published
Apr 17, 2024
Tracked Since
Feb 18, 2026