David Litchfield
24 exploits
Active since Jan 1999
Oracle 9i Database Release 2 - Buffer Overflow
Oracle 9i Database Release 2 - Buffer Overflow
All-Mail 1.1 - Remote Code Execution via Long MAIL FROM or RCPT TO Command
Oracle 9i Database Release 2 - Buffer Overflow
L-Soft LISTSERV 1.8 - Buffer Overflow in Web Archives
Internet Information Server 4.0 - URL Obfuscation via Long HTTP Request Method
Internet Information Server 4-5.1 - Information Exposure via Authentication Realm and NTLM Response
Internet Information Services 5.0 - Directory Listing via WebDAV Search
Microsoft Index Server - Info Disclosure
Microsoft SQL Server 7.0-2000 - Privilege Escalation
Microsoft SQL Server 2000 and MSDE 2000 - Remote Code Execution via UDP Port 1434
Microsoft Windows NT and Windows 2000 Terminal Services - Local Buffer Overflow via RPC Locator Service
Microsoft Windows 2000 and NT - Buffer Overflow in Phone Dialer via Malformed dialer.ini Entry
Microsoft SQL Server and MSDE - Denial of Service and Remote Code Execution via xp_displayparamstmt Buffer Overflow
Microsoft SQL Server and MSDE - Buffer Overflow in xp_showcolv Extended Stored Procedure
Microsoft Windows NT 4.0/4.0 SP1/4.0 SP2/4.0 SP3/4.0 SP4 - Server Operator to Administrator Privilege Escalation: System Key
Windows NT 4.0 - Buffer Overflow via Malformed Help File
Windows 2000 and NT - Buffer Overflow in Remote Access Service via Malformed Phonebook Entry
Microsoft Jet - Buffer Overflow in OpenDataSource Function
Oracle 11g - Multiple Privilege Escalation Vulnerabilities
Oracle 10g - Multiple Privilege Escalation Vulnerabilities
Netscape Enterprise Server <3.5.1 - Info Disclosure
Oracle9i Application Server 9.0.2 - MOD_ORADAV Access Control
Web Page Counter 2.70 - Denial of Service via Newline in HTTP Request