基础信息
项目名称:ezEngine/ezEngine
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1717601098058743808/1717601098096492544
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
Simple DirectMedia Layer SDL2_image 缓冲区错误漏洞 | 越界写入 | MPS-2018-14365 | CVE-2018-3977 | 高危 |
Simple DirectMedia Layer 安全漏洞 | 越界读取 | MPS-2018-4435 | CVE-2018-3837 | 中危 |
Simple DirectMedia Layer 安全漏洞 | 越界读取 | MPS-2018-4436 | CVE-2018-3838 | 中危 |
Simple DirectMedia Layer 安全漏洞 | 越界写入 | MPS-2018-4437 | CVE-2018-3839 | 高危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
sdl_image | 2.0.5 | 间接依赖 | 建议修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
MIT | 7 | 低 |
Zlib | 1 | 低 |
Apache-2.0 | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
Microsoft.VisualStudio.Validation | 14.1.111 | 间接依赖 | nuget |
sdl_image | 2.0.5 | 间接依赖 | |
Microsoft.VisualStudio.Shell.14.0 | 14.2.25123 | 间接依赖 | nuget |
KERNEL32.dll | 间接依赖 | ||
ozz-animation | 0.12.1 | 间接依赖 | |
Microsoft.VisualStudio.Utilities | 14.2.25123 | 间接依赖 | nuget |
Microsoft.VisualStudio.ProjectSystem | 14.1.80-pre | 间接依赖 | nuget |
api-ms-win-crt-convert-l1-1-0.dll | 间接依赖 | ||
miniz | 2.1.0 | 间接依赖 | |
System.Runtime.Extensions | 4.0.10 | 间接依赖 | nuget |
Microsoft.VisualStudio.Shell.Immutable.14.0 | 14.2.25123 | 间接依赖 | nuget |
Microsoft.VisualStudio.Composition | 14.0.50715-pre | 间接依赖 | nuget |
api-ms-win-crt-environment-l1-1-0.dll | 间接依赖 | ||
CommandLineParser | 2.5.0 | 间接依赖 | nuget |
Microsoft.VisualStudio.Shell.Interop.9.0 | 9.0.30729 | 间接依赖 | nuget |
Microsoft.VisualStudio.Imaging | 14.2.25123 | 间接依赖 | nuget |
Microsoft.VisualStudio.Shell.Interop | 7.10.6071 | 间接依赖 | nuget |
System.Runtime | 4.0.20 | 间接依赖 | nuget |
Microsoft.VisualStudio.OLE.Interop | 7.10.6070 | 间接依赖 | nuget |
api-ms-win-crt-string-l1-1-0.dll | 间接依赖 | ||
Microsoft.VisualStudio.TextManager.Interop | 7.10.6070 | 间接依赖 | nuget |
civetweb | 间接依赖 | ||
Microsoft.Composition | 1.0.30 | 间接依赖 | nuget |
MSVCP140.dll | 间接依赖 | ||
System.Globalization | 4.0.10 | 间接依赖 | nuget |
System.Threading | 4.0.10 | 间接依赖 | nuget |
api-ms-win-crt-math-l1-1-0.dll | 间接依赖 | ||
Microsoft.VisualStudio.Shell.Interop.12.0 | 12.0.30110 | 间接依赖 | nuget |
Microsoft.VisualStudio.SDK.VsixSuppression | 14.1.25 | 间接依赖 | nuget |
api-ms-win-crt-utility-l1-1-0.dll | 间接依赖 | ||
VCRUNTIME140.dll | 间接依赖 | ||
libc.so.6 | 间接依赖 | ||
System.Diagnostics.Debug | 4.0.10 | 间接依赖 | nuget |
OpenXR.Loader | 1.0.10.2 | 间接依赖 | nuget |
ADVAPI32.dll | 间接依赖 | ||
Microsoft.VisualStudio.Shell.Immutable.12.0 | 12.0.21003 | 间接依赖 | nuget |
recastnavigation | cci.20200511 | 间接依赖 | |
ld-linux-x86-64.so.2 | 间接依赖 | ||
Microsoft.Tpl.Dataflow | 4.5.24 | 间接依赖 | nuget |
Microsoft.VisualStudio.Threading | 14.1.131 | 间接依赖 | nuget |
Microsoft.VisualStudio.Shell.Interop.10.0 | 10.0.30319 | 间接依赖 | nuget |
rmlui | 间接依赖 | ||
api-ms-win-crt-heap-l1-1-0.dll | 间接依赖 | ||
System.Resources.ResourceManager | 4.0.0 | 间接依赖 | nuget |
Newtonsoft.Json | 13.0.2 | 间接依赖 | nuget |
api-ms-win-crt-stdio-l1-1-0.dll | 间接依赖 | ||
zstd | 间接依赖 | ||
Microsoft.VisualStudio.Shell.Interop.8.0 | 8.0.50727 | 间接依赖 | nuget |
System.Linq | 4.0.0 | 间接依赖 | nuget |
Microsoft.Diagnostics.Tracing.TraceEvent | 2.0.49 | 间接依赖 | nuget |
Microsoft.VisualStudio.Shell.Immutable.11.0 | 11.0.50727 | 间接依赖 | nuget |
OpenXR.Headers | 1.0.10.2 | 间接依赖 | nuget |
api-ms-win-crt-runtime-l1-1-0.dll | 间接依赖 | ||
Microsoft.Holographic.Remoting.OpenXr | 2.4.0 | 间接依赖 | nuget |
Microsoft.VisualStudio.Shell.Immutable.10.0 | 10.0.30319 | 间接依赖 | nuget |
libgcc_s.so.1 | 间接依赖 | ||
System.Collections | 4.0.10 | 间接依赖 | nuget |
libm.so.6 | 间接依赖 | ||
libstdc++.so.6 | 间接依赖 | ||
Microsoft.VisualStudio.Shell.Interop.11.0 | 11.0.61030 | 间接依赖 | nuget |
embree3 | 间接依赖 | ||
OpenDDS | 间接依赖 | ||
libpthread.so.0 | 间接依赖 | ||
miniz | 2.2.0 | 间接依赖 | |
Microsoft.VisualStudio.TextManager.Interop.8.0 | 8.0.50727 | 间接依赖 | nuget |
System.Collections.Immutable | 1.1.37 | 间接依赖 | nuget |