hdm
397 exploits
Active since Jan 1997
Juniper ScreenOS 6.2.0r15-6.2.0r18, 6.3.0r12-6.3.0r20 - Remote Admin Access via Hardcoded Password
rubyonrails/web_console < 2.1.2 and rubygems/web-console < 2.1.3 - Improper Access Control via X-Forwarded-For Header
2 stars
BIND < 9.5.0-P1, 9.4.2-P1, 9.3.5-P1 - DNS Cache Poisoning via Insufficient Transaction ID and Source Port Entropy
Samba is_known_pipename() Arbitrary Module Load
CVSS 9.8
Exim < 4.70 - Remote Code Execution via Crafted SMTP Headers
CVSS 9.8
Ruby on Rails JSON Processor YAML Deserialization Code Execution
Internet Explorer 9-11 and Windows - Privilege Escalation via WPAD NetBIOS Name Response
CVSS 8.8
Microsoft Windows 2000 SP4 through Vista - Remote Code Execution via Animated Cursor RIFF File
Microsoft Data Access Components 2.7-2.8 - Remote Code Execution via RDS.Dataspace ActiveX Control
Samsung Kies Air 2.1.207051 and 2.1.210161 - Improper Authentication via IP Address Spoofing
libupnp < 1.6.18 - Remote Code Execution via SSDP Unique Service Name Parsing
UPnP SSDP M-SEARCH Information Discovery
portable SDK for UPnP Devices < 1.6.18 - Stack-based Buffer Overflow via UDN Field in UDP Packet
libupnp 1.3.1 - Remote Code Execution via SSDP UDN Field Buffer Overflow
portable SDK for UPnP Devices 1.3.1 - Remote Code Execution via SSDP DeviceType Field
portable SDK for UPnP Devices 1.3.1 - Remote Code Execution via SSDP UDN Field Buffer Overflow
portable SDK for UPnP Devices 1.3.1 - Remote Code Execution via SSDP ServiceType Field
phpBB 2.x < 2.0.11 - Remote Code Execution via Double-Encoded Highlight Parameter
PHP < 5.3.12 and 5.4.x < 5.4.2 - Remote Code Execution via CGI Query String
CVSS 9.8
PHP < 5.3.13 and 5.4.x < 5.4.3 - Remote Code Execution via CGI Query String
Mac OS X 10.4 - Unsafe Attachment Handling in Mail Download Validation
Exim < 4.70 - Remote Code Execution via Crafted SMTP Headers
CVSS 9.8
libtiff < 3.8.2 - Stack-Based Buffer Overflow via Large tdir_count in TIFFFetchShortPair
libtiff < 3.8.2 - Stack-Based Buffer Overflow via Large tdir_count in TIFFFetchShortPair
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
CVSS 9.8