C Exploits

3,565 exploits tracked across all sources.

Sort: Activity Stars
CVE-2002-1561 EXPLOITDB c VERIFIED
Windows <XP - DoS
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.
by Trancer
CVE-2002-1561 EXPLOITDB c VERIFIED
Windows <XP - DoS
The RPC component in Windows 2000, Windows NT 4.0, and Windows XP allows remote attackers to cause a denial of service (disabled RPC service) via a malformed packet to the RPC Endpoint Mapper at TCP port 135, which triggers a null pointer dereference.
by lion
CVE-2002-1911 EXPLOITDB c VERIFIED
Zonelabs Zonealarm - Denial of Service
ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets (SYN flood). NOTE: the vendor was not able to reproduce the issue.
by Abraham Lincoln
CVE-2002-1230 EXPLOITDB c VERIFIED
NetDDE Agent - RCE
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation."
by Serus
CVE-2002-1230 EXPLOITDB c VERIFIED
NetDDE Agent - RCE
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute arbitrary code as LocalSystem via "shatter" style attack by sending a WM_COPYDATA message followed by a WM_TIMER message, as demonstrated by GetAd, aka "Flaw in Windows WM_TIMER Message Handling Could Enable Privilege Elevation."
by Serus
CVE-2002-0693 EXPLOITDB c VERIFIED
Microsoft Windows 2000 - Buffer Overflow
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute code via (1) a long parameter to the Alink function, or (2) script containing a long argument to the showHelp function.
by ipxodi
CVE-2001-0820 EXPLOITDB c VERIFIED
Gaztek Ghttp - Buffer Overflow
Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are passed to (1) the Log function in util.c, or (2) serveconnection in protocol.c.
by flea
CVE-2002-1522 EXPLOITDB c VERIFIED
PowerFTP <2.24 - RCE/DoS
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long USER argument.
by Morgan
EIP-2026-103171 EXPLOITDB c VERIFIED
MySQL 3.20.32/3.22.x/3.23.x - Null Root Password Weak Default Configuration (2)
by st0ic
CVE-2002-1816 EXPLOITDB CRITICAL c VERIFIED
Redshift Atphttpd < 0.4b - Buffer Overflow
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
by thread
CVSS 9.8
CVE-2002-0838 EXPLOITDB c VERIFIED
GV - Buffer Overflow
Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript file, which is processed by an unsafe call to sscanf.
by infamous42md
CVE-2002-0838 EXPLOITDB c VERIFIED
GV - Buffer Overflow
Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript file, which is processed by an unsafe call to sscanf.
by zen-parse
CVE-2002-1514 EXPLOITDB c VERIFIED
Borland InterBase - Privilege Escalation
gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "isc_init1.X" temporary file, as demonstrated by modifying the xinetdbd file.
by grazer
CVE-2002-1850 EXPLOITDB HIGH c VERIFIED
Apache HTTP Server - Improper Locking
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang and memory consumption) by causing a CGI script to send a large amount of data to stderr, which results in a read/write deadlock between httpd and the CGI script.
by K.C. Wong
CVSS 7.5
CVE-2002-1496 EXPLOITDB c VERIFIED
Null HTTP Server <0.5.0 - Buffer Overflow
Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in the Content-Length HTTP header.
by eSDee
CVE-2002-1487 EXPLOITDB c VERIFIED
Trillian <0.74 - DoS
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by sending the raw messages (1) 206, (2) 211, (3) 213, (4) 214, (5) 215, (6) 217, (7) 218, (8) 243, (9) 302, (10) 317, (11) 324, (12) 332, (13) 333, (14) 352, and (15) 367.
by Lance Fitz-Herbert
CVE-2002-1488 EXPLOITDB c VERIFIED
Trillian <0.75 - DoS
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via a PART message with (1) a missing channel or (2) a channel that the Trillian user is not in.
by Lance Fitz-Herbert
CVE-2002-1486 EXPLOITDB c VERIFIED
Trillian <0.74 - Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.
by Lance Fitz-Herbert
CVE-2002-1486 EXPLOITDB c VERIFIED
Trillian <0.74 - Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.
by Lance Fitz-Herbert
CVE-2002-1486 EXPLOITDB c VERIFIED
Trillian <0.74 - Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.
by Lance Fitz-Herbert
CVE-2002-1896 EXPLOITDB c VERIFIED
Alsaplayer - Buffer Overflow
Buffer overflow in Alsaplayer 0.99.71, when installed setuid root, allows local users to execute arbitrary code via a long (1) -f or (2) -o command line argument.
by zillion
CVE-2002-1486 EXPLOITDB c VERIFIED
Trillian <0.74 - Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.
by Lance Fitz-Herbert
CVE-2002-1486 EXPLOITDB c VERIFIED
Trillian <0.74 - Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service and possibly execute arbitrary code via (1) a large response from the server, (2) a JOIN with a long channel name, (3) a long "raw 221" message, (4) a PRIVMSG with a long nickname, or (5) a long response from an IDENT server.
by Lance Fitz-Herbert
CVE-2002-1492 EXPLOITDB c VERIFIED
Cisco VPN 5000 Client <5.2.7/5.2.8 - Privilege Escalation
Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel.
by zillion
CVE-2002-1492 EXPLOITDB c VERIFIED
Cisco VPN 5000 Client <5.2.7/5.2.8 - Privilege Escalation
Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allow local users to gain root privileges via (1) close_tunnel and (2) open_tunnel.
by BrainStorm