Michal Zalewski
41 exploits
Active since Dec 1997
Mozilla based browsers <2.0.0.2 - CSRF
Microsoft Windows XP - TCP Packet Information Leakage
Microsoft Windows 2000 - Denial of Service via Long Telnet Logon Command with Backspace
Microsoft Internet Explorer 6.0.2900.2180 - Buffer Overflow
Internet Explorer <6.0 - RCE
Microsoft Internet Explorer - Denial of Service via Crafted JPEG Images
Microsoft Internet Explorer 6 - Script Action Handlers 'mshtml.dll' Denial of Service
Internet Explorer - Denial of Service via Nested OBJECT Tags
Samba - Directory Traversal via NETBIOS Name in %m Macro
OpenSSH - Remote Code Execution via CRC-32 Compensation Attack
XFree86 xlib - Buffer Overflow via Long DISPLAY Environment Variable or -display Parameter
CoreGraphics - Remote Code Execution or Denial of Service via Argument Processing
Novell NetWare - Buffer Overflow via Long URL
Mozilla Firefox <32 - Info Disclosure
Safari < 4.0 - Cross-Site Scripting via Event Handler
Lynx 2.8 - Remote Buffer Overflow
Browsers Browsers - Navigation Download Trick
Ascom COLTSOHO / Brocade Fabric OS / MatchBox / Win98/NT4 / Solaris / Xyplex - SNMP World Writeable Community
Apache HTTP Server - Denial of Service via Excessive Slash Characters in GET Requests
INN 2.2.2 - Remote Code Execution via Long Message ID in Cancel Request
OpenSSH - Directory Traversal via Malicious SCP Server
Eric Allman Sendmail 8.8.x - Socket Hijack
vixie_cron - Arbitrary Command Execution via Predictable Temporary File
Vixie cron <3.0.1 - Privilege Escalation
perl - Local Privilege Escalation via suidperl Escape Sequence Injection