C Exploits
3,570 exploits tracked across all sources.
Slackware 7.1 - '/usr/bin/mail' Local Privilege Escalation
by kengz
Freebsd Ja-xklock < 2.7.1 - Buffer Overflow
Buffer overflow in ja-xklock 2.7.1 and earlier allows local users to gain root privileges.
by dethy
Ja-elvis < 1.8.4_1 - Buffer Overflow
Buffer overflow in ja-elvis and ko-helvis ports of elvis allow local users to gain root privileges.
by dethy
HP Tru64 UNIX - Buffer Overflow
Buffer overflow in HP Tru64 UNIX allows local users to execute arbitrary code via a long argument to /usr/bin/at.
by Cody Tubbs
BIND 8 - Buffer Overflow
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
by Multiple
BIND 8 - Buffer Overflow
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
by LSD-PLaNET
BIND 8 - Buffer Overflow
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
by LSD-PLaNET
BIND 8 - Buffer Overflow
Buffer overflow in transaction signature (TSIG) handling code in BIND 8 allows remote attackers to gain root privileges.
by Gneisenau
Atrium Software Mercur - Buffer Overflow
Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command.
by Martin Rakhmanoff
Debian Linux - Buffer Overflow
Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
by MaXX
Marconi Forethought - Denial of Service
Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management interfaces via a malformed packet with the SYN-FIN and More Fragments attributes set.
by J.K. Garvey
Linux kernel <2.4,2.2 - Info Disclosure
Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call.
by Chris Evans
CORE SDI SSH1 - RCE
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.
by Michal Zalewski
Davide Libenzi Xmail < 0.66 - Buffer Overflow
Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel functions.
by isno
SUN Solaris - Buffer Overflow
Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "arg0" (process name) argument.
by UNYUN
HP Tru64 UNIX <5.1a-4.0f - Buffer Overflow
Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via (1) su, (2) chsh, (3) passwd, (4) chfn, (5) dxchpwd, and (6) libc.
by K2
SCO mscreen - Buffer Overflow
Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscreenrc file.
by K2
Vim - Info Disclosure
vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swap files, when the victim is editing the file in a world writable directory.
by zen-parse
SAM Lantinga Splitvt < 1.6.4 - Buffer Overflow
Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.
by Michel Kaempf
Solaris 2.6-7 - Buffer Overflow
Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the terminal name argument.
by Pablo Sor
Windows NT 4.0 - DoS
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allows local users to modify the permissions to "No Access" and disable Winsock network connectivity to cause a denial of service, aka the "Winsock Mutex" vulnerability.
by Arne Vidstrom
CVSS 7.1
Baltimore Technologies Websweeper - Denial of Service
Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of service (memory exhaustion) via an extremely large HTTP Referrer: header.
by honoriak
icecast <1.3.8beta2 - RCE
Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands.
by CyRaX
Eeye Digital Security Iris - Denial of Service
eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to crash when a user views the packet.
by grazer
By Source