C Exploits

3,620 exploits tracked across all sources.

Sort: Activity Stars
CVE-2020-27930 GITHUB HIGH c
iPadOS < 14.2 - Remote Code Execution via Maliciously Crafted Font
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. Processing a maliciously crafted font may lead to arbitrary code execution.
by X1cT34m
4 stars
CVSS 7.8
CVE-2021-3156 GITHUB HIGH c
Sudo Heap-Based Buffer Overflow
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
by lockedbyte
690 stars
CVSS 7.8
CVE-2020-9273 GITHUB HIGH c
ProFTPD 1.3.7 - Use-After-Free in Memory Pool via Data Transfer Channel Interruption
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.
by lockedbyte
690 stars
CVSS 8.8
CVE-2020-28018 GITHUB CRITICAL c
Exim 4.90-4.94.1 - Use-After-Free in SMTP Reset
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.
by lockedbyte
690 stars
CVSS 9.8
CVE-2019-18634 GITHUB HIGH c
sudo 1.7.1-1.8.25 - Stack-based Buffer Overflow via pwfeedback
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the privileged sudo process. (pwfeedback is a default setting in Linux Mint and elementary OS; however, it is NOT the default for upstream and many other packages, and would exist only if enabled by an administrator.) The attacker needs to deliver a long string to the stdin of getln() in tgetpass.c.
by lockedbyte
690 stars
CVSS 7.8
CVE-2021-22555 EXPLOITDB HIGH c VERIFIED
Netfilter x_tables Heap OOB Write Privilege Escalation
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
by TheFloW
CVSS 8.3
CVE-2018-8120 GITHUB HIGH c
Windows SetImeInfoEx Win32k NULL Pointer Dereference
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.
by AmazingOut
CVSS 7.0
CVE-2017-1768 GITHUB MEDIUM c
IBM Security Guardium Big Data Intelligence 3.1 - Exposure of Sensitive Information via Error Message
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information about its environment, users, or associated data. IBM X-Force ID: 136471.
by AmazingOut
CVSS 4.3
CVE-2016-7255 GITHUB HIGH c
Microsoft Windows - Privilege Escalation
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
by AmazingOut
CVSS 7.8
CVE-2016-0095 GITHUB HIGH c
Microsoft Windows - Local Privilege Escalation via Kernel-Mode Driver
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0093, CVE-2016-0094, and CVE-2016-0096.
by AmazingOut
CVSS 7.8
CVE-2015-2546 GITHUB HIGH c
Microsoft Windows - Local Privilege Escalation via Win32k Memory Corruption
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Elevation of Privilege Vulnerability," a different vulnerability than CVE-2015-2511, CVE-2015-2517, and CVE-2015-2518.
by AmazingOut
CVSS 8.2
CVE-2015-0057 GITHUB c
Windows win32k.sys - Local Privilege Escalation via Crafted Application
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
by AmazingOut
CVE-2014-4113 GITHUB HIGH c
Microsoft Windows - Privilege Escalation
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, as exploited in the wild in October 2014, aka "Win32k.sys Elevation of Privilege Vulnerability."
by AmazingOut
CVSS 7.8
CVE-2014-1767 GITHUB c
Microsoft Windows - Privilege Escalation
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
by AmazingOut
CVE-2010-2883 GITHUB HIGH c
Adobe Reader/Acrobat <9.4-8.2.5 - Buffer Overflow
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a PDF document with a long field in a Smart INdependent Glyphlets (SING) table in a TTF font, as exploited in the wild in September 2010. NOTE: some of these details are obtained from third party information.
by AmazingOut
CVSS 7.3
CVE-2020-12352 EXPLOITDB MEDIUM c
Linux Kernel 5.4-5.4.71 - Unauthenticated Information Disclosure via BlueZ Access Control
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
by Google Security Research
CVSS 6.5
CVE-2021-3156 EXPLOITDB HIGH c
Sudo Heap-Based Buffer Overflow
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
by nu11secur1ty
CVSS 7.8
EIP-2026-114725 EXPLOITDB c
Solaris 10 (SPARC) - 'dtprintinfo' Local Privilege Escalation (2)
by Marco Ivaldi
EIP-2026-114724 EXPLOITDB c
Solaris 10 (SPARC) - 'dtprintinfo' Local Privilege Escalation (1)
by Marco Ivaldi
EIP-2026-114723 EXPLOITDB c
Solaris 10 (Intel) - 'dtprintinfo' Local Privilege Escalation (3)
by Marco Ivaldi
EIP-2026-114722 EXPLOITDB c
Solaris 10 (Intel) - 'dtprintinfo' Local Privilege Escalation (2)
by Marco Ivaldi
EIP-2026-114721 EXPLOITDB c
Solaris 10 (SPARC) - 'dtprintinfo' Local Privilege Escalation (3)
by Marco Ivaldi
CVE-2017-11014 GITHUB HIGH c
Android for MSM - Buffer Overflow in Roam Neighbor Action Report Measurement Request IE Parser
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while parsing a Measurement Request IE in a Roam Neighbor Action Report, a buffer overflow can occur.
by ScottyBauer
682 stars
CVSS 7.8
CVE-2017-11013 GITHUB HIGH c
Android for MSM - Buffer Overflow in UnpackCore Function
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, countOffset (in function UnpackCore) is increased for each loop, while there is no boundary check against "pIe->arraybound".
by ScottyBauer
682 stars
CVSS 7.8
CVE-2018-9355 GITHUB CRITICAL c
Android - Out-of-bounds Write in bta_dm_sdp_result
In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74016921.
by ScottyBauer
682 stars
CVSS 9.8