C Exploits

3,571 exploits tracked across all sources.

Sort: Activity Stars
CVE-1999-1008 EXPLOITDB c VERIFIED
xsoldier - Privilege Escalation via Long Argument
xsoldier program allows local users to gain root access via a long argument.
by zorgon
CVE-2001-0029 EXPLOITDB c VERIFIED
oops WWW proxy server <1.4.6 - RCE
Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrary commands via a long host or domain name that is obtained from a reverse DNS lookup.
by diman
CVE-2001-0082 EXPLOITDB c VERIFIED
Check Point VPN-1/FireWall-1 <4.1 SP2 - Auth Bypass
Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.
by Thomas Lopatic
CVE-2001-0028 EXPLOITDB c VERIFIED
oops WWW proxy <1.5.2 - RCE
Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters.
by CyRaX
CVE-2000-0917 EXPLOITDB c VERIFIED
LPRng 3.6.24 - RCE
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
by sk8
CVE-2000-0917 EXPLOITDB c VERIFIED
LPRng 3.6.24 - RCE
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
by DiGiT
EIP-2026-103081 EXPLOITDB c VERIFIED
BFTPd 1.0.12 - Remote Overflow
by korty
CVE-2001-0028 EXPLOITDB c VERIFIED
oops WWW proxy <1.5.2 - RCE
Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute arbitrary commands via a large number of " (quotation) characters.
by diman
CVE-2000-0967 EXPLOITDB c VERIFIED
PHP <4 - RCE
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands by triggering error messages that are improperly written to the error logs.
by Gneisenau
EIP-2026-102887 EXPLOITDB c VERIFIED
Kwintv - Local Buffer Overflow
by Cody Tubbs
EIP-2026-102852 EXPLOITDB c VERIFIED
gnome_segv - Local Buffer Overflow
by Cody Tubbs
CVE-2001-0050 EXPLOITDB c VERIFIED
Colten Edwards Bitchx - Buffer Overflow
Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary commands via an IP address that resolves to a long DNS hostname or domain name.
by nimrood
CVE-2000-1134 EXPLOITDB c VERIFIED
Unix Shell < - Local File Overwrite
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack.
by t--zen
EIP-2026-102850 EXPLOITDB c VERIFIED
GnomeHack - Local Buffer Overflow
by Cody Tubbs
EIP-2026-102835 EXPLOITDB c VERIFIED
expect (/usr/bin/expect) - Local Buffer Overflow
by isox
CVE-2000-0305 EXPLOITDB c VERIFIED
Beos - Resource Management Error
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a denial of service by sending a large number of identical fragmented IP packets, aka jolt2 or the "IP Fragment Reassembly" vulnerability.
by phonix
CVE-2000-0844 EXPLOITDB c VERIFIED
Caldera Openlinux Ebuilder - Access Control
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
by sk8
CVE-2001-0066 EXPLOITDB c VERIFIED
Secure Locate - Memory Corruption
Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset value that accesses memory outside of the intended buffer.
by Michel Kaempf
CVE-2000-1083 EXPLOITDB c VERIFIED
SQL Server - Buffer Overflow
The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
by David Litchfield
CVE-2000-1085 EXPLOITDB c VERIFIED
Microsoft SQL Server 2000-MSDE - Buffer Overflow
The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
by @stake
CVE-2000-1081 EXPLOITDB c VERIFIED
SQL Server - Buffer Overflow
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the length of a buffer before calling the srv_paraminfo function in the SQL Server API for Extended Stored Procedures (XP), which allows an attacker to cause a denial of service or execute arbitrary commands, aka the "Extended Stored Procedure Parameter Parsing" vulnerability.
by David Litchfield
CVE-1999-0977 EXPLOITDB c VERIFIED
SUN Solaris - Buffer Overflow
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
by Optyx
CVE-2000-0699 EXPLOITDB c VERIFIED
Hp-ux - Denial of Service
Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbitrary commands via format strings in the PASS command.
by venglin
CVE-2000-1186 EXPLOITDB c VERIFIED
phf CGI - Buffer Overflow
Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of arguments and including a long MIME header.
by proton
CVE-2000-1119 EXPLOITDB c VERIFIED
IBM AIX <4.3.x - Buffer Overflow
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a long "x=" argument.
by Last Stage of Delirium