Exploitdb Exploits

237 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-118607 EXPLOITDB c++ VERIFIED
GlobalLink 'GLChat.ocx' 2.5.1 - ActiveX Control 'ChatRoom()' Remote Buffer Overflow
by Knell
CVE-2007-3039 EXPLOITDB c++ VERIFIED
Microsoft Message Queuing - Memory Corruption
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.
by axis
CVE-2007-6166 EXPLOITDB c++ VERIFIED
Apple QuickTime <7.3.1 - Buffer Overflow
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.
by InTeL
CVE-2007-5094 EXPLOITDB c++ VERIFIED
Ipswitch Imail - Memory Corruption
Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary code via a set of four different e-mail messages with a long boundary parameter in a certain malformed Content-Type header line, the string "MIME" by itself on a line in the header, and a long Content-Transfer-Encoding header line.
by axis
CVE-2004-2513 EXPLOITDB c++ VERIFIED
Mercury (Pegasus) Mail 4.01 - RCE
Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via a long SELECT command.
by Heretic2
CVE-2007-4440 EXPLOITDB c++ VERIFIED
MercuryS SMTP <4.51 - Buffer Overflow
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.
by ZhenHan.Liu
CVE-2007-4375 EXPLOITDB c++ VERIFIED
Diskeeper 9 - Info Disclosure/DoS
The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versions exposes a memory comparison function via RPC over TCP, which allows remote attackers to (1) obtain sensitive information (process memory contents), as demonstrated by an attack that obtains module base addresses to defeat Address Space Layout Randomization (ASLR); or (2) cause a denial of service (application crash) via an out-of-bounds address.
by Pravus
CVE-2007-4257 EXPLOITDB c++ VERIFIED
Live for Speed S1-S2 - RCE
Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary code via (1) a .spr file (single player replay file) containing a long user name or (2) a .ply file containing a long number plate string, different vectors than CVE-2007-4140.
by n00b
CVE-2007-4257 EXPLOITDB c++ VERIFIED
Live for Speed S1-S2 - RCE
Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary code via (1) a .spr file (single player replay file) containing a long user name or (2) a .ply file containing a long number plate string, different vectors than CVE-2007-4140.
by n00b
CVE-2007-3614 EXPLOITDB c++ VERIFIED
Sap DB - Buffer Overflow
Multiple stack-based buffer overflows in waHTTP.exe (aka the SAP DB Web Server) in SAP DB, possibly 7.3 through 7.5, allow remote attackers to execute arbitrary code via (1) a certain cookie value; (2) a certain additional parameter, related to sapdbwa_GetQueryString; and other unspecified vectors related to "numerous other fields."
by Heretic2
CVE-2007-1770 EXPLOITDB c++ VERIFIED
Esri Arcsde - Buffer Overflow
Buffer overflow in the ArcSDE service (giomgr) in Environmental Systems Research Institute (ESRI) ArcGIS before 9.2 Service Pack 2, when using three tiered ArcSDE configurations, allows remote attackers to cause a denial of service (giomgr crash) and execute arbitrary code via long parameters in crafted requests.
by Heretic2
CVE-2007-3006 EXPLOITDB c++ VERIFIED
Acoustica Mp3 CD Burner - Buffer Overflow
Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .asx playlist file with a REF element containing a long string in the HREF attribute. NOTE: it was later claimed that 4.51 Build 147 is also affected.
by n00b
CVE-2007-2888 EXPLOITDB c++ VERIFIED
UltraISO <8.6.2.2011 - Buffer Overflow
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrary code via a long FILE string (filename) in a .cue file, a related issue to CVE-2007-2761. NOTE: some details are obtained from third party information.
by n00b
CVE-2007-1765 EXPLOITDB c++ VERIFIED
Microsoft Windows 2000 < 6 - Denial of Service
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.
by devcode
CVE-2007-1511 EXPLOITDB c++ VERIFIED
Frontbase Relational Database Server < 4.2.7 - Buffer Overflow
Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privileges for creating a stored procedure, to execute arbitrary code via a CREATE PROCEDURE request with a long procedure name.
by Heretic2
CVE-2007-1568 EXPLOITDB c++ VERIFIED
Daansystems Newsreactor - Buffer Overflow
Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded article with a long filename.
by Marsu
CVE-2007-1568 EXPLOITDB c++ VERIFIED
Daansystems Newsreactor - Buffer Overflow
Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via a yEnc (yEncode) encoded article with a long filename.
by Marsu
CVE-2007-1569 EXPLOITDB c++ VERIFIED
Newsbin Pro - Buffer Overflow
Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrary code via a yEnc (yEncode) encoded article with a long filename, as demonstrated using a .nzb file. NOTE: some of these details are obtained from third party information.
by Marsu
CVE-2007-1075 EXPLOITDB c++ VERIFIED
TurboFTP 5.30 - DoS
TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large number of newline characters.
by Marsu
CVE-2007-1080 EXPLOITDB c++ VERIFIED
TurboFTP <5.30 Build 572 - Buffer Overflow
Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1) long filename in a response to a LIST command, and (2) a long response to a CWD command.
by Marsu
CVE-2007-1079 EXPLOITDB c++ VERIFIED
Rhino Software, Inc. FTP Voyager <14.0.0.3 - Buffer Overflow
Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a denial of service (crash) via a long response to a CWD command, which triggers the overflow when the user aborts the command.
by Marsu
CVE-2007-1082 EXPLOITDB c++ VERIFIED
FTP Explorer <1.0.1.52 - DoS
FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CPU consumption) via a long response to a PWD command.
by Marsu
CVE-2007-0790 EXPLOITDB c++ VERIFIED
SmartFTP 2.0.1002 - Buffer Overflow
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
by Marsu
CVE-2007-0825 EXPLOITDB c++ VERIFIED
FlashFXP 3.4.0 - DoS
FlashFXP 3.4.0 build 1145 allows remote servers to cause a denial of service (CPU consumption) via a response to a PWD command that contains a long string with deeply nested directory structure, possibly due to a buffer overflow.
by Marsu
EIP-2026-117510 EXPLOITDB c++ VERIFIED
Microsoft Visual C++ - '.RC Resource Files' Local Buffer Overflow
by porkythepig