h1ch4m

23 exploits Active since Feb 2005
CVE-2013-10057 EXPLOITDB HIGH html WORKING POC
Synactis PDF In-The-Box ActiveX - Buffer Overflow
A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifically the ConnectToSynactis method. When a long string is passed to this method—intended to populate the ldCmdLine argument of a WinExec call—a strcpy operation overwrites a saved TRegistry class pointer on the stack. This allows remote attackers to execute arbitrary code in the context of the user by enticing them to visit a malicious webpage that instantiates the vulnerable ActiveX control. The vulnerability was discovered via its use in third-party software such as Logic Print 2013.
CVE-2011-10008 EXPLOITDB HIGH perl WORKING POC
MPlayer Lite r33064 - Buffer Overflow
A stack-based buffer overflow vulnerability exists in MPlayer Lite r33064 due to improper bounds checking when handling M3U playlist files containing long http:// URL entries. An attacker can craft a malicious .m3u file with a specially formatted URL that triggers a stack overflow when processed by the player, particularly via drag-and-drop interaction. This flaw allows for control of the execution flow through SEH overwrite and a DEP bypass using a ROP chain that leverages known gadgets in loaded DLLs. Successful exploitation may result in arbitrary code execution with the privileges of the current user.
CVE-2013-10057 METASPLOIT HIGH ruby WORKING POC
Synactis PDF In-The-Box ActiveX - Buffer Overflow
A stack-based buffer overflow vulnerability exists in Synactis PDF In-The-Box ActiveX control (PDF_IN_1.ocx), specifically the ConnectToSynactis method. When a long string is passed to this method—intended to populate the ldCmdLine argument of a WinExec call—a strcpy operation overwrites a saved TRegistry class pointer on the stack. This allows remote attackers to execute arbitrary code in the context of the user by enticing them to visit a malicious webpage that instantiates the vulnerable ActiveX control. The vulnerability was discovered via its use in third-party software such as Logic Print 2013.
EIP-2026-119185 EXPLOITDB ruby WORKING POC
Synactis PDF In-The-Box - ConnectToSynactic Stack Buffer Overflow (Metasploit)
EIP-2026-118161 EXPLOITDB perl WORKING POC
Word List Builder - Local Buffer Overflow (SEH)
EIP-2026-118162 EXPLOITDB ruby WORKING POC
Word List Builder 1.0 - Local Buffer Overflow (Metasploit)
EIP-2026-118163 EXPLOITDB perl WORKING POC
Word Splash Pro 9.5 - Local Buffer Overflow
CVE-2004-0964 EXPLOITDB ruby WORKING POC
Zinf <2.2.1 - RCE
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.
EIP-2026-117647 EXPLOITDB perl WORKING POC
MPlayer Lite r33064 - '.m3u' Local Buffer Overflow (DEP Bypass)
EIP-2026-116955 EXPLOITDB perl WORKING POC
Chasys Media Player 2.0 - Local Buffer Overflow (SEH)
EIP-2026-116785 EXPLOITDB perl WORKING POC
AnvSoft Any Video Converter 4.3.6 - Unicode Buffer Overflow
EIP-2026-116706 EXPLOITDB ruby WORKING POC
ABBS Electronic Flashcards 2.1 - Local Buffer Overflow (Metasploit)
EIP-2026-116527 EXPLOITDB perl WORKING POC
WaveMax Sound Editor 4.5.1 - Denial of Service (PoC)
EIP-2026-116693 EXPLOITDB perl WORKING POC
A-PDF All to MP3 Converter 2.0.0 - '.wav' Local Buffer Overflow
EIP-2026-116695 EXPLOITDB perl WORKING POC
A-PDF All to MP3 Converter 2.0.0 - DEP Bypass
EIP-2026-116699 EXPLOITDB perl WORKING POC
A-PDF Wav to MP3 Converter 1.2.0 - DEP Bypass
EIP-2026-116702 EXPLOITDB perl WORKING POC
ABBS Audio Media Player 3.0 - '.lst' Local Buffer Overflow (SEH)
EIP-2026-116703 EXPLOITDB ruby WORKING POC
ABBS Audio Media Player 3.0 - Local Buffer Overflow (Metasploit)
EIP-2026-116705 EXPLOITDB perl WORKING POC
ABBS Electronic Flash Cards 2.1 - '.fcd' Local Buffer Overflow
EIP-2026-115144 EXPLOITDB perl WORKING POC
Digital Audio Editor 7.6.0.237 - Local Crash (PoC)
EIP-2026-115303 EXPLOITDB text WORKING POC
FreeTrim MP3 2.2.3 - Denial of Service
EIP-2026-115292 EXPLOITDB perl WORKING POC
Free Audio Converter 7.1.5 - Denial of Service (PoC)
EIP-2026-115187 EXPLOITDB perl WORKING POC
Easy DVD Creator - Local Crash (PoC)