Exploitdb Exploits

3,138 exploits tracked across all sources.

Sort: Activity Stars
CVE-2010-1280 EXPLOITDB HIGH c VERIFIED
Adobe Shockwave Player <11.5.7.609 - RCE/DoS
Adobe Shockwave Player before 11.5.7.609 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted .dir (aka Director) file, related to (1) an erroneous dereference and (2) a certain Shock.dir file.
by LiquidWorm
CVSS 8.8
EIP-2026-119085 EXPLOITDB c VERIFIED
Rebellion Aliens vs Predator 2.22 - Multiple Memory Corruption Vulnerabilities
by Luigi Auriemma
CVE-2007-2192 EXPLOITDB c VERIFIED
Photofiltre Studio 8.1.1 - Buffer Overflow via Crafted TIFF File
Buffer overflow in Photofiltre Studio 8.1.1 allows user-assisted remote attackers to execute arbitrary code via a crafted .tif file.
by fl0 fl0w
CVE-2010-0105 EXPLOITDB c VERIFIED
Apple Mac OS X 10.5.8 and 10.6.x < 10.6.5 - Denial of Service via Directory Hard Link Manipulation
The hfs implementation in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 supports hard links to directories and does not prevent certain deeply nested directory structures, which allows local users to cause a denial of service (filesystem corruption) via a crafted application that calls the mkdir and link functions, related to the fsck_hfs program in the diskdev_cmds component.
by Maksymilian Arciemowicz
EIP-2026-115065 EXPLOITDB c VERIFIED
CommView 6.1 (Build 636) - Local Blue Screen of Death (Denial of Service)
by p4r4N0ID
CVE-2010-1894 EXPLOITDB c
Windows XP SP2-SP3 and Windows Server 2003 SP2 - Privilege Escalation via Win32k Exception Handling
The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified exceptions, which allows local users to gain privileges via a crafted application, aka "Win32k Exception Handling Vulnerability."
by MJ0011
CVE-2010-1734 EXPLOITDB c
Windows 2000, XP, and Server 2003 - Denial of Service via SfnINSTRING Function
The SfnINSTRING function in win32k.sys in the kernel in Microsoft Windows 2000, XP, and Server 2003 allows local users to cause a denial of service (system crash) via a 0x18d value in the second argument (aka the Msg argument) of a PostMessage function call for the DDEMLEvent window.
by MJ0011
CVE-2010-0740 EXPLOITDB c VERIFIED
OpenSSL 0.9.8f-0.9.8m - Denial of Service via Malformed TLS Record
The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f through 0.9.8m allows remote attackers to cause a denial of service (crash) via a malformed record in a TLS connection that triggers a NULL pointer dereference, related to the minor version number. NOTE: some of these details are obtained from third party information.
by Andi
EIP-2026-117476 EXPLOITDB c
Micropoint ProActive Denfense 'Mp110013.sys' 1.3.10123.0 - Local Privilege Escalation
by MJ0011
EIP-2026-119288 EXPLOITDB c VERIFIED
WinSoftMagic Photo Editor - '.png' Remote Buffer Overflow
by eidelweiss
EIP-2026-118490 EXPLOITDB c VERIFIED
EasyFTP Server 1.7.0.2 - 'MKD' (Authenticated) Remote Buffer Overflow
by x90c
EIP-2026-118935 EXPLOITDB c VERIFIED
MX Simulator Server - Remote Buffer Overflow
by Salvatore Fresta
EIP-2026-103525 EXPLOITDB c VERIFIED
Jinais IRC Server 0.1.8 - Null Pointer (PoC)
by Salvatore Fresta
EIP-2026-117451 EXPLOITDB c VERIFIED
Mediacoder - '.lst' Local Buffer Overflow
by fl0 fl0w
CVE-2010-20114 EXPLOITDB HIGH c VERIFIED
VariCAD EN <2010-2.05 - Buffer Overflow
VariCAD EN up to and including version 2010-2.05 is vulnerable to a stack-based buffer overflow when parsing .dwb drawing files. The application fails to properly validate the length of input data embedded in the file, allowing a crafted .dwb file to overwrite critical memory structures. This flaw can be exploited locally by convincing a user to open a malicious file, resulting in arbitrary code execution.
by n00b
EIP-2026-103471 EXPLOITDB c VERIFIED
FreeBSD / OpenBSD - 'ftpd' Null Pointer Dereference Denial of Service
by kingcope
CVE-2010-0425 EXPLOITDB c VERIFIED
IBM WebSphere Application Server 6.1-6.1.0.30 - Remote Code Execution via ISAPI Module Orphaned Callback Pointers
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."
by Brett Gervasoni
EIP-2026-100671 EXPLOITDB c VERIFIED
FreeBSD 8.0 / OpenBSD 4.x - 'ftpd' Null Pointer Dereference Denial of Service
by kingcope
EIP-2026-117458 EXPLOITDB c VERIFIED
Mediacoder 0.7.3.4605 - Local Buffer Overflow
by fl0 fl0w
EIP-2026-119554 EXPLOITDB c
RadASM - '.rap' file Local Buffer Overflow
by fl0 fl0w
EIP-2026-116142 EXPLOITDB c VERIFIED
RadASM 2.2.1.6 - '.rap' Local Buffer Overflow (PoC)
by fl0 fl0w
EIP-2026-118039 EXPLOITDB c VERIFIED
UltraISO 9.3.6.2750 - Local Buffer Overflow
by fl0 fl0w
CVE-2010-0233 EXPLOITDB c VERIFIED
Microsoft Windows - Memory Corruption
Double free vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allows local users to gain privileges via a crafted application, aka "Windows Kernel Double Free Vulnerability."
by Tavis Ormandy
CVE-2009-0546 EXPLOITDB c VERIFIED
NewsGator FeedDemon <2.7 - Buffer Overflow
Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbitrary code via a long text attribute in an outline element in a .opml file.
by fl0 fl0w
EIP-2026-116449 EXPLOITDB c VERIFIED
UltraISO 9.3.6.2750 - Local Buffer Overflow (PoC)
by fl0 fl0w