C++ Exploits
245 exploits tracked across all sources.
Mnet Soft Factory Nodemanager Professional - Buffer Overflow
Stack-based buffer overflow in NodeManager Professional 2.00 allows remote attackers to execute arbitrary commands via a LinkDown-Trap packet that contains a long OCTET-STRING in the Trap variable-bindings field.
by Tan Chew Keong
Apple iTunes - Playlist Buffer Overflow Download Shellcode
by ATmaCA
Windows 2000/2003 - Privilege Escalation
LSASS (Local Security Authority Subsystem Service) of Windows 2000 Server and Windows Server 2003 does not properly validate connection information, which allows local users to gain privileges via a specially-designed program.
by Cesar Cerrudo
GNU Mailutils <0.6.90 - RCE
Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a crafted e-mail.
by infamous41md
Symantec Gateway Security - DNS Cache Poisoning
The DNS proxy (DNSd) for multiple Symantec Gateway Security products allows remote attackers to poison the DNS cache via a malicious DNS server query response that contains authoritative or additional records.
by fryxar
Windows NT-Server 2003 - Buffer Overflow
Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary code via long (1) LB_DIR messages to ListBox or (2) CB_DIR messages to ComboBox controls in a privileged application.
by Brett Moore
Microsoft Windows XP/2000/2003 - Message Queuing Service Heap Overflow
by DaveK
EarthStation 5 - Search Service Remote File Deletion
by random nut
Microsoft SQL Server < - DoS
Microsoft SQL Server 7, 2000, and MSDE allows local or remote authenticated users to cause a denial of service (crash or hang) via a long request to a named pipe.
by refdom
Microsoft Data Engine - Memory Corruption
Multiple buffer overflows in the Resolution Service for Microsoft SQL Server 2000 and Microsoft Desktop Engine 2000 (MSDE) allow remote attackers to cause a denial of service or execute arbitrary code via UDP packets to port 1434 in which (1) a 0x04 byte that causes the SQL Monitor thread to generate a long registry key name, or (2) a 0x08 byte with a long string causes heap corruption, as exploited by the Slammer/Sapphire worm.
by David Litchfield
Koules 1.4 - Buffer Overflow
Buffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument.
by Synnergy.net
Microsoft Office 2000 - Code Injection
When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as riched20.dll and msi.dll, which could allow an attacker to execute arbitrary commands by inserting a Trojan Horse DLL into the same directory as the document.
by Georgi Guninski
Microsoft Windows 2000 - Buffer Overflow
Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long WM_USER message, aka the "Still Image Service Privilege Escalation" vulnerability.
by dildog
Windows 2000 Telnet Client - Open Redirect
The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capture and replay the NTLM challenge/response via a telnet:// URL that points to the malicious server, aka the "Windows 2000 Telnet Client NTLM Authentication" vulnerability.
by @stake
Microsoft Windows 2000 - Denial of Service
The NetBIOS Name Server (NBNS) protocol does not perform authentication, which allows remote attackers to cause a denial of service by sending a spoofed Name Conflict or Name Release datagram, aka the "NetBIOS Name Server Protocol Spoofing" vulnerability.
by Sir Dystic
Windows 2000 - Privilege Escalation
The Service Control Manager (SCM) in Windows 2000 creates predictable named pipes, which allows a local user with console access to gain administrator privileges, aka the "Service Control Manager Named Pipe Impersonation" vulnerability.
by Maceo
Cheyenne InocuLAN Anti-Virus Server <4.0 - Local Privilege Escalation
Cheyenne InocuLAN Anti-Virus Server in Inoculan 4.0 before Service Pack 2 creates an update directory with "EVERYONE FULL CONTROL" permissions, which allows local users to cause Inoculan's antivirus update feature to install a Trojan horse dll.
by Paul Boyer
Cisco Ios - Denial of Service
Land IP denial of service.
by Konrad Malewski
By Source