C Exploits

3,550 exploits tracked across all sources.

Sort: Activity Stars
CVE-2017-2483 EXPLOITDB HIGH c VERIFIED
Apple Iphone OS < 10.2.1 - Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watchOS before 3.2 is affected. The issue involves the "Kernel" component. A buffer overflow allows attackers to execute arbitrary code in a privileged context via a crafted app.
by Google Security Research
CVSS 7.8
CVE-2017-2489 EXPLOITDB MEDIUM c VERIFIED
Apple Mac OS X < 10.12.3 - Information Disclosure
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app.
by Google Security Research
CVSS 5.5
CVE-2017-2443 EXPLOITDB HIGH c VERIFIED
Apple Mac OS X < 10.12.3 - Memory Corruption
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graphics Driver" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.
by Google Security Research
CVSS 7.8
CVE-2017-0576 GITHUB HIGH c
Linux Kernel - Integer Overflow
An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33544431. References: QC-CR#1103089.
by derrekr
87 stars
CVSS 7.0
CVE-2017-0531 GITHUB MEDIUM c
Linux Kernel - Information Disclosure
An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32877245. References: QC-CR#1087469.
by derrekr
87 stars
CVSS 4.7
CVE-2017-0521 GITHUB HIGH c
Linux Kernel - Integer Overflow
An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32919951. References: QC-CR#1097709.
by derrekr
87 stars
CVSS 7.0
CVE-2017-0392 GITHUB MEDIUM c
Google Android - Denial of Service
A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32577290.
by derrekr
87 stars
CVSS 5.5
CVE-2016-8477 GITHUB MEDIUM c
Android Kernel 3.10/3.18 - Info Disclosure
An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32720522. References: QC-CR#1090007.
by derrekr
87 stars
CVSS 4.7
CVE-2016-8413 GITHUB MEDIUM c
Android Kernel 3.10/3.18 - Info Disclosure
An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32709702. References: QC-CR#518731.
by derrekr
87 stars
CVSS 4.7
CVE-2017-7397 EXPLOITDB HIGH c
BackBox Linux 4.6 - DoS
BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packets with Martian source IP addresses (as defined in RFC 1812 section 5.3.7). This product enables net.ipv4.conf.all.log_martians by default. NOTE: the vendor reports "It has been proved that this vulnerability has no foundation and it is totally fake and based on false assumptions.
by FarazPajohan
CVSS 7.5
EIP-2026-115774 EXPLOITDB c
Microsoft Visual Studio 2015 update 3 - Denial of Service
by Peter Baris
CVE-2015-5736 EXPLOITDB c VERIFIED
Fortinet FortiClient <5.2.4 - RCE
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call.
by sickness
CVE-2015-5736 EXPLOITDB c VERIFIED
Fortinet FortiClient <5.2.4 - RCE
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the callback function in a (1) 0x220024 or (2) 0x220028 ioctl call.
by sickness
CVE-2016-9793 EXPLOITDB HIGH c
Linux Kernel < 3.12.69 - Memory Corruption
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUFFORCE or (2) SO_RCVBUFFORCE option.
by Andrey Konovalov
CVSS 7.8
CVE-2017-8225 EXPLOITDB CRITICAL c
Wificam Wireless IP Camera (p2p) Firm... - Insufficiently Protected Credentials
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and an empty loginpas parameter in the URI.
by PierreKimSec
CVSS 9.8
CVE-2017-6178 EXPLOITDB HIGH c
Usbpcap - NULL Pointer Dereference
The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference.
by Parvez Anwar
CVSS 7.8
CVE-2017-6444 EXPLOITDB HIGH c
Mikrotik Routeros - Denial of Service
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets. After the attacker stops the exploit, the CPU usage is 100% and the router requires a reboot for normal operation.
by FarazPajohan
CVSS 7.5
CVE-2017-6074 EXPLOITDB HIGH c
Linux Kernel < 3.2.86 - Double Free
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
by Andrey Konovalov
CVSS 7.8
CVE-2017-6074 EXPLOITDB HIGH c
Linux Kernel < 3.2.86 - Double Free
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call.
by Andrey Konovalov
CVSS 7.8
CVE-2017-5972 EXPLOITDB HIGH c
Linux Kernel < 3.19.8 - Denial of Service
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demonstrated by an attack against the kernel-3.10.0 package in CentOS Linux 7. NOTE: third parties have been unable to discern any relationship between the GitHub Engineering finding and the Trigemini.c attack code.
by FarazPajohan
CVSS 7.5
CVE-2017-5329 EXPLOITDB HIGH c VERIFIED
Paloaltonetworks Terminal Services Agent < 7.0.6 - Out-of-Bounds Write
Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation.
by Parvez Anwar
CVSS 7.8
CVE-2017-3730 EXPLOITDB HIGH c
OpenSSL <1.1.0d - DoS
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack.
by Guido Vranken
CVSS 7.5
CVE-2017-2353 EXPLOITDB HIGH c VERIFIED
Apple <10.12.3 - RCE/DoS
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
by Google Security Research
CVSS 7.8
CVE-2017-2360 EXPLOITDB HIGH c VERIFIED
Apple <10.2.1, <10.12.3, <10.1.1, <3.1.3 - RCE/DoS
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS before 10.1.1 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
by Google Security Research
CVSS 7.8
CVE-2015-6565 EXPLOITDB c
Openbsd Openssh - Access Control
sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disruption) or possibly have unspecified other impact by writing to a device, as demonstrated by writing an escape sequence.
by Federico Bento