Exploitdb Exploits

237 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-0167 EXPLOITDB MEDIUM c++ VERIFIED
Microsoft Windows 10 - Information Disclosure
An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system, a.k.a. "Windows Kernel Information Disclosure Vulnerability."
by Google Security Research
CVSS 5.5
EIP-2026-119525 EXPLOITDB c++ VERIFIED
Fortinet FortiClient 5.2.3 (Windows 10 x86) - Local Privilege Escalation
by sickness
CVE-2016-5195 EXPLOITDB HIGH c++ VERIFIED
Canonical Ubuntu Linux < 3.2.83 - Race Condition
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."
by Gabriele Bonacini
CVSS 7.0
CVE-2016-3388 EXPLOITDB MEDIUM c++ VERIFIED
Microsoft Edge - Access Control
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3387.
by Google Security Research
CVSS 5.3
CVE-2016-3387 EXPLOITDB HIGH c++ VERIFIED
Microsoft Edge - Access Control
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3388.
by Google Security Research
CVSS 7.5
CVE-2016-7188 EXPLOITDB HIGH c++ VERIFIED
Microsoft Windows 10 - Access Control
The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulnerability."
by Google Security Research
CVSS 7.8
EIP-2026-117229 EXPLOITDB c++
GE Proficy HMI/SCADA CIMPLICITY 8.2 - Local Privilege Escalation
by Zhou Yu
CVE-2016-0400 EXPLOITDB MEDIUM c++
IBM WebSphere eXtreme Scale <7.1.0.3-8.6.0.8 - CRLF Injection
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
by blomster81
CVSS 6.1
CVE-2016-0151 EXPLOITDB HIGH c++ VERIFIED
Microsoft Windows 10 1507 - Improper Privilege Management
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."
by Google Security Research
CVSS 7.8
EIP-2026-100055 EXPLOITDB c++
Google Android - 'sensord' Local Privilege Escalation
by s0m3b0dy
CVE-2015-8396 EXPLOITDB CRITICAL c++
Grassroots DICOM <2.6.2 - RCE
Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attackers to execute arbitrary code via crafted header dimensions in a DICOM image file, which triggers a buffer overflow.
by Stelios Tsampas
CVSS 10.0
CVE-2014-4113 EXPLOITDB HIGH c++
Microsoft Windows - Privilege Escalation
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."
by anonymous
CVSS 7.8
EIP-2026-115779 EXPLOITDB c++
Microsoft Windows - 'win32k.sys' Denial of Service
by Kedamsky
EIP-2026-115270 EXPLOITDB c++ VERIFIED
FortKnox Personal Firewall 9.0.305.0/10.0.305.0 - Kernel Driver 'fortknoxfw.sys' Memory Corruption
by Arash Allebrahim
EIP-2026-116570 EXPLOITDB c++ VERIFIED
Wireshark 1.6.0/1.8.2 - Buffer Overflow (PoC)
by X-h4ck
CVE-2001-0198 EXPLOITDB c++ VERIFIED
Apple Quicktime - Buffer Overflow
Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a long HREF parameter in an EMBED tag.
by UNYUN
CVE-2012-3456 EXPLOITDB c++ VERIFIED
Calligra < 2.4.3 - Memory Corruption
Heap-based buffer overflow in the read function in filters/words/msword-odf/wv2/src/styles.cpp in the Microsoft import filter in Calligra 2.4.3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted ODF style in an ODF document. NOTE: this is the same vulnerability as CVE-2012-3455, but it was SPLIT by the CNA even though Calligra and KOffice share the same codebase.
by Charlie Miller
EIP-2026-116040 EXPLOITDB c++
PC Tools Firewall Plus 7.0.0.123 - Local Denial of Service
by 0in
EIP-2026-116051 EXPLOITDB c++ VERIFIED
PEamp - '.mp3' Memory Corruption (PoC)
by Ayrbyte
EIP-2026-115824 EXPLOITDB c++
Microsoft Windows XP - 'win32k.sys' Local Kernel Denial of Service
by Lufeng Li
EIP-2026-117721 EXPLOITDB c++ VERIFIED
OpenDrive 1.3.141 - Local Password Disclosure
by Glafkos Charalambous
CVE-2010-0361 EXPLOITDB c++
SUN Java System Web Server - Memory Corruption
Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long URI in an HTTP OPTIONS request.
by dmc
CVE-2010-0361 EXPLOITDB c++
SUN Java System Web Server - Memory Corruption
Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update 7 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via a long URI in an HTTP OPTIONS request.
by dmc
EIP-2026-118064 EXPLOITDB c++ VERIFIED
VirtualDJ Trial 6.0.6 'New Year Edition' - '.m3u' Local Overflow
by fl0 fl0w
CVE-2009-4873 EXPLOITDB c++ VERIFIED
Rhinosoft Serv-u - Memory Corruption
Stack-based buffer overflow in the HTTP server in Rhino Software Serv-U Web Client 9.0.0.5 allows remote attackers to cause a denial of service (server crash) or execute arbitrary code via a long Session cookie.
by Megumi Yanagishita