C Exploits

3,550 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-1084 EXPLOITDB HIGH c VERIFIED
Freebsd < 11.2 - Memory Corruption
In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. This results in the possibility a poorly written process could be cause a stack overflow.
by Qualys Corporation
CVSS 7.5
CVE-2017-1084 EXPLOITDB HIGH c VERIFIED
Freebsd < 11.2 - Memory Corruption
In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. This results in the possibility a poorly written process could be cause a stack overflow.
by Qualys Corporation
CVSS 7.5
CVE-2017-1000367 EXPLOITDB MEDIUM c
Todd Miller's sudo <1.8.20 - Info Disclosure & Command Execution
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_ttyname() function resulting in information disclosure and command execution.
by Qualys Corporation
CVSS 6.4
CVE-2017-7004 EXPLOITDB HIGH c VERIFIED
Apple <10.3.2, <10.12.5 - Privilege Escalation
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The issue involves the "Security" component. A race condition allows attackers to bypass intended entitlement restrictions for sending XPC messages via a crafted app.
by Google Security Research
CVSS 7.0
CVE-2017-4916 EXPLOITDB MEDIUM c VERIFIED
VMware Workstation Pro/Player - DoS
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Successful exploitation of this issue may allow host users with normal user privileges to trigger a denial-of-service in a Windows host machine.
by Borja Merino
CVSS 6.5
CVE-2017-7472 EXPLOITDB MEDIUM c VERIFIED
Linux kernel <4.10.13 - DoS
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumption) via a series of KEY_REQKEY_DEFL_THREAD_KEYRING keyctl_set_reqkey_keyring calls.
by Marcus Meissner
CVSS 5.5
CVE-2017-2671 EXPLOITDB MEDIUM c VERIFIED
Linux Kernel < 4.10.8 - Denial of Service
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock and consequently cannot ensure that disconnect function calls are safe, which allows local users to cause a denial of service (panic) by leveraging access to the protocol value of IPPROTO_ICMP in a socket system call.
by Daniel Jiang
CVSS 5.5
EIP-2026-103652 EXPLOITDB c VERIFIED
Skia Graphics Library - Heap Overflow due to Rounding Error in SkEdge::setLine
by Google Security Research
CVE-2017-2501 EXPLOITDB HIGH c VERIFIED
Apple Iphone OS < 10.3.2 - Race Condition
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
by Google Security Research
CVSS 7.0
EIP-2026-103409 EXPLOITDB c VERIFIED
Apple macOS/iOS Kernel - Memory Disclosure Due to Lack of Bounds Checking in netagent Socket Option Handling
by Google Security Research
CVE-2017-6978 EXPLOITDB HIGH c VERIFIED
Apple <10.12.5 - RCE/DoS
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibility Framework" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
by Google Security Research
CVSS 7.8
CVE-2017-4915 EXPLOITDB HIGH c VERIFIED
VMware Workstation Pro/Player - Privilege Escalation
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation of this issue may allow unprivileged host users to escalate their privileges to root in a Linux host machine.
by Google Security Research
CVSS 7.8
CVE-2017-9150 EXPLOITDB MEDIUM c VERIFIED
Linux kernel <4.11.1 - Info Disclosure
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allows local users to obtain sensitive address information via crafted bpf system calls.
by Google Security Research
CVSS 5.5
CVE-2017-8422 EXPLOITDB HIGH c
KDE Kauth < 5.33 - Authentication Bypass by Spoofing
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
by Stealth
CVSS 7.8
CVE-2017-8849 EXPLOITDB HIGH c
Smb4k < 2.0.0 - Improper Input Validation
smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service.
by Stealth
CVSS 7.8
CVE-2017-7308 EXPLOITDB HIGH c VERIFIED
AF_PACKET packet_set_ring Privilege Escalation
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (integer signedness error and out-of-bounds write), or gain privileges (if the CAP_NET_RAW capability is held), via crafted system calls.
by Andrey Konovalov
CVSS 7.8
CVE-2017-8339 EXPLOITDB MEDIUM c
Watchguard Panda Antivirus - Memory Corruption
PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoControl request to \\.\PSMEMDriver.
by Peter Baris
CVSS 5.5
CVE-2017-3576 EXPLOITDB HIGH c VERIFIED
Oracle VM VirtualBox <5.0.38-5.1.20 - RCE
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
by Google Security Research
CVSS 8.8
CVE-2017-7874 EXPLOITDB c
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
by Nassim Asrir
CVE-2017-2490 EXPLOITDB HIGH c VERIFIED
Apple Iphone OS < 10.2.1 - Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
by Google Security Research
CVSS 7.8
CVE-2017-2473 EXPLOITDB HIGH c VERIFIED
Apple Iphone OS < 10.2.1 - Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
by Google Security Research
CVSS 7.8
CVE-2017-2474 EXPLOITDB HIGH c VERIFIED
Apple <10.3 - RCE
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. An off-by-one error allows attackers to execute arbitrary code in a privileged context via a crafted app.
by Google Security Research
CVSS 7.8
CVE-2017-2478 EXPLOITDB HIGH c VERIFIED
Apple Iphone OS < 10.2.1 - Race Condition
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A race condition allows attackers to execute arbitrary code in a privileged context via a crafted app.
by Google Security Research
CVSS 7.0
CVE-2017-2482 EXPLOITDB HIGH c VERIFIED
Apple Iphone OS < 10.2.1 - Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.
by Google Security Research
CVSS 7.8
CVE-2017-2472 EXPLOITDB HIGH c VERIFIED
Apple Iphone OS < 10.2.1 - Use After Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
by Google Security Research
CVSS 7.8