Francisco Falcon
45 exploits
Active since Aug 2008
Oracle Sun Products Suite <3.0.1 - RCE
Windows Media Center - Arbitrary File Read via Crafted .mcl File
Anzio WePO <3.2.19-3.2.24 - Buffer Overflow
Foxit Reader <3.0 Build 1506 - Buffer Overflow
SAP NetWeaver - Buffer Overflow in Message Server _MsJ2EE_AddStatistics() Function
CVSS 9.8
VLC media player 0.9.2 - Remote Code Execution via XSPF Playlist Negative Identifier Tag
Firebird SQL 1.5-1.5.5, 2.0-2.0.5, 2.1-2.1.2, 2.5 Beta 1 - Denial of Service via Malformed op_connect_request Message
Novell iManager 2.7, 2.7.3, 2.7.3 FTF2 - Denial of Service via Long Tree Parameter
IBM WebSphere Application Server <7.0.0.13 - CSRF
Oracle VirtualBox < 4.3.8 Local Guest-to-Host RCE via 3D Acceleration
Sophos Web Appliance <3.7.9.1, <3.8-3.8.1.1 - Privilege Escalation
Sophos Web Appliance <3.7.9.1, <3.8.1.1 - Command Injection
Sophos Web Appliance <3.7.9.1, <3.8-3.8.1.1 - Privilege Escalation
Zavio IP Cameras <1.6.3 - Command Injection
CVSS 9.8
Vivotek PT7135 Firmware 0300a and 0400a - OS Command Injection via system.ntp Parameter
CVSS 8.8
MayGion IP Camera Firmware < 2013.04.22 (05.53) - Remote Code Execution via Long Filename
TP-Link IP Camera - Command Injection
CVSS 9.8
D-Link DCS and WCS Firmware - Unauthenticated Remote Access via Hard-coded Credentials
CVSS 5.3
FreeBSD <9.3p39, 10.1p31, 10.2p14 - DoS
CVSS 6.2
FreeBSD - Local Privilege Escalation and Arbitrary Kernel Memory Read via SCTP Stream ID