Francisco Falcon
45 exploits
Active since Aug 2008
Oracle VirtualBox < 4.3.8 Local Guest-to-Host RCE via 3D Acceleration
Rejected
Sophos Web Appliance <3.7.9.1, <3.8.1.1 - Command Injection
Zavio IP Cameras <1.6.3 - Command Injection
CVSS 9.8
Zavio IP Cameras <1.6.3 - Auth Bypass
CVSS 7.5
Vivotek PT7135 Firmware 0300a and 0400a - Buffer Overflow via RTSP Authorization Header
CVSS 9.8
Vivotek PT7135 Firmware 0300a and 0400a - Authentication Bypass via RTSP Packet
CVSS 5.3
Vivotek PT7135 Firmware 0300a and 0400a - Path Traversal via GET Request
CVSS 6.5
D-Link DCS-2102 and DCS-2121 Firmware - Authentication Bypass via UPnP ASF-MP4 Streaming
CVSS 5.3
D-Link DCS and WCS Firmware - Unauthenticated Information Disclosure via lums.cgi
CVSS 5.3
D-Link DCS-3411 and Multiple Camera Firmware - Unauthenticated Information Disclosure via RTSP Session Cookie
CVSS 7.5
FreeBSD 9.3-10.1 - Denial of Service and Privilege Escalation via VT_WAITACTIVE ioctl
MayGion IP Camera Firmware < 09.27 - Path Traversal via Default URI
Dlink Dcs-3411 Firmware - OS Command Injection
CVSS 9.8
Vivotek PT7135 Firmware 0300a/0400a - Cleartext Credential Storage Exposes Sensitive Information
CVSS 7.5
Oracle VM VirtualBox < 4.3.8 - Authenticated Remote Code Execution via 3D Acceleration Network Pointer
TP-LINK TL-SC 3130, TL-SC 3130G, TL-SC 3171G, TL-SC 4171G < 1.6.18p12 - Security Bypass via Hard-coded Credentials
CVSS 7.5
Zavio IP Cameras <1.6.03 - Auth Bypass
CVSS 7.5
Novell iManager <=2.7.3 FTF2 - Authenticated RCE via EnteredClassID/NewClassName
Windows Media Center - Arbitrary File Read via Crafted .mcl File
Oracle VirtualBox < 4.3.8 Local Guest-to-Host RCE via 3D Acceleration
Foxit Reader <3.0 Build 1506 - Buffer Overflow
Sophos Web Appliance <3.7.9.1, <3.8.1.1 - Command Injection
Sophos Web Appliance <3.7.9.1, <3.8-3.8.1.1 - Privilege Escalation
Blue Coat Malware Analysis Appliance <4.2.5 & Malware Analyzer G2 <3.5 - RCE via VM Protection Bypass
CVSS 9.3