jduck
345 exploits
Active since Mar 1998
Windows NT and Windows 2000 - Unauthenticated Remote Access via Null Password
rsh/rlogin Service - Info Disclosure
rsh/rlogin Service - Info Disclosure
HP-UX - Unauthenticated Remote Login via Default Null Password
rsh/rlogin Service - Info Disclosure
Android < 2.3.4 - Unauthorized SD Card Data Exposure via Crafted Content URIs
Android < 5.1.1 - Remote Code Execution via Crafted MPEG-4 Data
Titan FTP Server < 8.10.1125 - Authenticated Path Traversal via XCRC Command
Coppermine Photo Gallery < 1.4.14 - Remote Code Execution via ImageMagick Picture Processing Parameters
TWiki 20030201 - Remote Code Execution via Search Function Shell Metacharacters
Android API < 16.0 - Remote Code Execution via WebView.addJavascriptInterface
Oracle VM Server Virtual Server Agent Command Injection
TWiki 02-Sep-2004 and earlier - Remote Code Execution via Rev Parameter Shell Metacharacter Injection
Horde Groupware 1.2.10 and Horde 3.3.12 - Remote Code Execution via Trojanized JavaScript Template
Wireshark 0.9.15-1.0.10 and 1.2.0-1.2.5 - Denial of Service via Malformed LWRES Packet
OpenX < 2.8.1 - Authenticated Arbitrary File Upload and Remote Code Execution via Banner Edit
HP Operations Dashboard - Unauthenticated Remote Code Execution via Default j2deployer Credentials
JBoss JMX Console Deployer Upload and Execute
CVSS 5.3
Wireshark 0.9.15-1.0.10 and 1.2.0-1.2.5 - Denial of Service via Malformed LWRES Packet
Exim4 string_format Function Heap Buffer Overflow
CVSS 7.8
JBoss JMX Console Deployer Upload and Execute
CVSS 5.3
Sun Java System Web Server 7.0 Update 7 - Stack-Based Buffer Overflow via WebDAV OPTIONS Request
TikiWiki 1.9.8 - Remote Code Execution via tiki-graph_formula.php f Parameter
Adobe Acrobat and Reader < 9.2 - Remote Code Execution
HP-UX - Remote Code Execution via wu-ftpd SITE EXEC Format String