C Exploits

3,619 exploits tracked across all sources.

Sort: Activity Stars
CVE-2019-13272 EXPLOITDB HIGH c
Linux Polkit pkexec helper PTRACE_TRACEME local root exploit
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
by Ujas Dhami
CVSS 7.8
EIP-2026-103824 EXPLOITDB c
zlog 1.2.15 - Buffer Overflow
by LIWEI
EIP-2026-102926 EXPLOITDB c
Mini-XML 3.2 - Heap Overflow
by LIWEI
CVE-2021-40444 GITHUB HIGH c
Microsoft Office Word Malicious MSHTML RCE
<p>Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability by using specially-crafted Microsoft Office documents.</p> <p>An attacker could craft a malicious ActiveX control to be used by a Microsoft Office document that hosts the browser rendering engine. The attacker would then have to convince the user to open the malicious document. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p> <p>Microsoft Defender Antivirus and Microsoft Defender for Endpoint both provide detection and protections for the known vulnerability. Customers should keep antimalware products up to date. Customers who utilize automatic updates do not need to take additional action. Enterprise customers who manage updates should select the detection build 1.349.22.0 or newer and deploy it across their environments. Microsoft Defender for Endpoint alerts will be displayed as: “Suspicious Cpl File Execution”.</p> <p>Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This may include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.</p> <p>Please see the <strong>Mitigations</strong> and <strong>Workaround</strong> sections for important information about steps you can take to protect your system from this vulnerability.</p> <p><strong>UPDATE</strong> September 14, 2021: Microsoft has released security updates to address this vulnerability. Please see the Security Updates table for the applicable update for your system. We recommend that you install these updates immediately. Please see the FAQ for important information about which updates are applicable to your system.</p>
by codecat007
8 stars
CVSS 8.8
CVE-2021-3156 GITHUB HIGH c
Sudo Heap-Based Buffer Overflow
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
by codecat007
8 stars
CVSS 7.8
CVE-2019-2025 GITHUB HIGH c
Android - Use-After-Free in binder_thread_read
In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-116855682References: Upstream kernel
by codecat007
8 stars
CVSS 7.8
CVE-2018-9539 GITHUB HIGH c
Android 8.0-9 - Use-After-Free via ClearKey CAS Descrambler Race Condition
In the ClearKey CAS descrambler, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-113027383
by codecat007
8 stars
CVSS 7.0
CVE-2018-9515 GITHUB HIGH c
Android - Memory Corruption in sdcardfs inode Operations
In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-111641492 References: N/A
by codecat007
8 stars
CVSS 7.8
CVE-2018-9424 GITHUB HIGH c
Android - Out-of-bounds Write in CryptoPlugin::decrypt
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
by codecat007
8 stars
CVSS 7.8
CVE-2018-9344 GITHUB HIGH c
Android - Use-After-Free in DescramblerImpl.cpp
In several functions of DescramblerImpl.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
by codecat007
8 stars
CVSS 7.8
CVE-2017-6262 GITHUB HIGH c
Android NVIDIA Driver - Use-After-Free via Race Condition
NVIDIA driver contains a vulnerability where it is possible a use after free malfunction can occur due to a race condition which could enable unauthorized code execution and possibly lead to elevation of privileges. This issue is rated as high. Product: Android. Version: N/A. Android ID: A-38045794. References: N-CVE-2017-6262.
by codecat007
8 stars
CVSS 7.0
CVE-2017-13273 GITHUB HIGH c
Android Kernel - Local Privilege Escalation via Race Condition in xt_qtaguid.c
In xt_qtaguid.c, there is a race condition due to insufficient locking. This could lead to local elevation of privileges with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-65853158.
by codecat007
8 stars
CVSS 7.0
CVE-2017-13253 GITHUB HIGH c
Android 8.0 8.1 - Out-of-bounds Write in CryptoPlugin::decrypt
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-71389378.
by codecat007
8 stars
CVSS 7.8
CVE-2017-13232 GITHUB HIGH c
Android 5.1.1-8.1 - Local Information Disclosure via Audioserver Log Statement
In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that may not be NULL terminated. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68953950.
by codecat007
8 stars
CVSS 7.5
CVE-2017-0553 GITHUB HIGH c
Android 5.0.2 5.1.1 6.0 6.0.1 7.0 7.1.1 - Elevation of Privilege via libnl Integer Overflow
An elevation of privilege vulnerability in libnl could enable a local malicious application to execute arbitrary code within the context of the Wi-Fi service. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32342065. NOTE: this issue also exists in the upstream libnl before 3.3.0 library.
by codecat007
8 stars
CVSS 7.0
CVE-2017-0508 GITHUB HIGH c
Android Kernel-3.18 - Privilege Escalation
An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33940449.
by codecat007
8 stars
CVSS 7.8
CVE-2017-0479 GITHUB HIGH c
Android 4.4.4-7.1.1 - Privilege Escalation
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32707507.
by codecat007
8 stars
CVSS 7.8
CVE-2017-0477 GITHUB HIGH c
Android 7.1.1 - Remote Code Execution via Crafted File in libgdx
A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbitrary code within the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses this library. Product: Android. Versions: 7.1.1. Android ID: A-33621647.
by codecat007
8 stars
CVSS 7.8
CVE-2017-0426 GITHUB MEDIUM c
Android 7.0-7.1.1 - Unauthorized Data Access via Filesystem
An information disclosure vulnerability in the Filesystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32799236.
by codecat007
8 stars
CVSS 5.5
CVE-2017-0415 GITHUB HIGH c
Android <7.1.1 - Privilege Escalation
An elevation of privilege vulnerability in Mediaserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-32706020.
by codecat007
8 stars
CVSS 7.8
CVE-2017-0386 GITHUB HIGH c
Android <7.1 - Privilege Escalation
An elevation of privilege vulnerability in the libnl library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32255299.
by codecat007
8 stars
CVSS 7.8
CVE-2017-0334 GITHUB MEDIUM c
NVIDIA GPU Driver for Android Kernel-3.18 - Information Disclosure via Local Application
An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.18. Android ID: A-33245849. References: N-CVE-2017-0334.
by codecat007
8 stars
CVSS 5.5
CVE-2017-0333 GITHUB HIGH c
Android Kernel 3.18 - Privilege Escalation
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-33899363. References: N-CVE-2017-0333.
by codecat007
8 stars
CVSS 7.8
CVE-2016-8482 GITHUB HIGH c
Android - Elevation of Privilege in NVIDIA GPU Driver
An elevation of privilege vulnerability in the NVIDIA GPU driver. Product: Android. Versions: Android kernel. Android ID: A-31799863. References: N-CVE-2016-8482.
by codecat007
8 stars
CVSS 7.8
CVE-2016-8479 GITHUB HIGH c
Android Kernel <3.18 - Privilege Escalation
An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31824853. References: QC-CR#1093687.
by codecat007
8 stars
CVSS 7.8