Exploitdb Exploits

462 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-10149 EXPLOITDB CRITICAL bash VERIFIED
Exim 4.87 - 4.91 Local Privilege Escalation
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
by Marco Ivaldi
CVSS 9.8
EIP-2026-102800 EXPLOITDB bash VERIFIED
CentOS 7.6 - 'ptrace_scope' Privilege Escalation
by s4vitar
EIP-2026-103025 EXPLOITDB bash
Ubuntu 18.04 - 'lxd' Privilege Escalation
by s4vitar
EIP-2026-104639 EXPLOITDB bash
Opencart 3.0.3.2 - 'extension/feed/google_base' Denial of Service (PoC)
by Todor Donev
EIP-2026-101860 EXPLOITDB bash
Netgear DGN2200 / DGND3700 - Admin Password Disclosure
by Social Engineering Neo
CVE-2019-11415 EXPLOITDB HIGH bash
Intelbras IWR 3000N 1.5.0 - Denial of Service via Malformed Login Request
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the \""} string to v1/system/login.
by Social Engineering Neo
CVSS 7.5
CVE-2019-11060 EXPLOITDB HIGH bash
ASUS HG100 Firmware < 1.05.12 - Unauthenticated Denial of Service via Slowloris HTTP Attack
The web api server on Port 8080 of ASUS HG100 firmware up to 1.05.12, which is vulnerable to Slowloris HTTP Denial of Service: an attacker can cause a Denial of Service (DoS) by sending headers very slowly to keep HTTP or HTTPS connections and associated resources alive for a long period of time. CVSS 3.0 Base score 7.4 (Availability impacts). CVSS vector: (CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).
by YinT Wang
CVSS 7.5
CVE-2018-11492 EXPLOITDB HIGH bash
ASUS HG100 Firmware - Denial of Service via IPv4 Packet Flood
ASUS HG100 devices allow denial of service via an IPv4 packet flood.
by YinT Wang
CVSS 7.5
CVE-2018-9276 EXPLOITDB HIGH bash
PRTG Network Monitor < 18.2.39 - Authenticated OS Command Injection via Sensor or Notification Parameters
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.
by M4LV0
CVSS 7.2
CVE-2019-9599 EXPLOITDB HIGH bash
AirDroid < 4.2.1.6 - Denial of Service via sdctl/comm/lite_auth Requests
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneous sdctl/comm/lite_auth/ requests.
by s4vitar
CVSS 7.5
CVE-2019-6973 EXPLOITDB HIGH bash
gSOAP 2.8.x - Denial of Service via Incomplete HTTP Requests
Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server (based on gSOAP 2.8.x) is configured for an iterative queueing approach (aka non-threaded operation) with a timeout of several seconds.
by Andrew Watson
CVSS 7.5
CVE-2018-14665 EXPLOITDB MEDIUM bash
xorg-x11-server <1.20.3 - Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
by Marco Ivaldi
CVSS 6.6
CVE-2019-12181 EXPLOITDB HIGH bash
Serv-U FTP Server prepareinstallation Privilege Escalation
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
by bcoles
CVSS 8.8
CVE-2017-5899 EXPLOITDB HIGH bash
s-nail < 14.8.5 - Path Traversal via randstr Argument
Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local users to write to arbitrary files and consequently gain root privileges via a .. (dot dot) in the randstr argument.
by bcoles
CVSS 7.0
EIP-2026-103764 EXPLOITDB bash
ASAN/SUID - Local Privilege Escalation
by bcoles
CVE-2018-18955 EXPLOITDB HIGH bash
Linux Nested User Namespace idmap Limit Local Privilege Escalation
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.
by bcoles
CVSS 7.0
CVE-2018-18955 EXPLOITDB HIGH bash
Linux Nested User Namespace idmap Limit Local Privilege Escalation
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.
by bcoles
CVSS 7.0
CVE-2017-4915 EXPLOITDB HIGH bash
VMware Workstation Pro/Player - Privilege Escalation
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.
by bcoles
CVSS 7.8
EIP-2026-103772 EXPLOITDB bash
Deepin Linux 15 - 'lastore-daemon' Local Privilege Escalation
by bcoles
CVE-2018-14665 EXPLOITDB MEDIUM bash
xorg-x11-server <1.20.3 - Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
by Marco Ivaldi
CVSS 6.6
CVE-2018-18955 EXPLOITDB HIGH bash
Linux Nested User Namespace idmap Limit Local Privilege Escalation
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.
by bcoles
CVSS 7.0
CVE-2018-18955 EXPLOITDB HIGH bash
Linux Nested User Namespace idmap Limit Local Privilege Escalation
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.
by bcoles
CVSS 7.0
CVE-2018-16323 EXPLOITDB MEDIUM bash
ImageMagick < 6.9.10-9 - Information Exposure via XBM Image Processing
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.
by ttffdd
CVSS 6.5
CVE-2018-14665 EXPLOITDB MEDIUM bash
xorg-x11-server <1.20.3 - Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.
by Marco Ivaldi
CVSS 6.6
CVE-2018-25396 EXPLOITDB HIGH bash
Heatmiser Wifi Thermostat 1.7 Credential Disclosure via networkSetup.htm
Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attackers can request the networkSetup.htm endpoint and extract plaintext username and password values from HTML form fields to gain administrative access to the thermostat.
by d0wnp0ur
CVSS 7.5