Exploitdb Exploits

3,149 exploits tracked across all sources.

Sort: Activity Stars
CVE-2008-5745 EXPLOITDB c VERIFIED
Microsoft Windows Media Player <11.0.5721.5260 - DoS
Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, including 11.0.5721.5260, allows remote attackers to cause a denial of service (application crash) via a crafted (1) WAV, (2) SND, or (3) MID file. NOTE: this has been incorrectly reported as a code-execution vulnerability. NOTE: it is not clear whether this issue is related to CVE-2008-4927.
by anonymous
CVE-2008-4113 EXPLOITDB c VERIFIED
Linux Kernel < 2.6.25.14 - Information Disclosure
The sctp_getsockopt_hmac_ident function in net/sctp/socket.c in the Stream Control Transmission Protocol (sctp) implementation in the Linux kernel before 2.6.26.4, when the SCTP-AUTH extension is enabled, relies on an untrusted length value to limit copying of data from kernel memory, which allows local users to obtain sensitive information via a crafted SCTP_HMAC_IDENT IOCTL request involving the sctp_getsockopt function.
by Jon Oberheide
CVE-2008-5736 EXPLOITDB c VERIFIED
Freebsd - Access Control
Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p1, 7.0 before 7.0-RELEASE-p7, 7.1 before 7.1-RC2, and 7 before 7.1-PRERELEASE allow local users to gain privileges via unknown attack vectors related to function pointers that are "not properly initialized" for (1) netgraph sockets and (2) bluetooth sockets.
by Don Bailey
CVE-2008-5713 EXPLOITDB c VERIFIED
Linux Kernel <2.6.25 - DoS
The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users to cause a denial of service (soft lockup) by sending a large amount of network traffic, as demonstrated by multiple simultaneous invocations of the Netperf benchmark application in UDP_STREAM mode.
by Herbert Xu
CVE-2008-5377 EXPLOITDB c VERIFIED
CUPS 1.3.8 - Local File Overwrite
pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333.
by Jon Oberheide
CVE-2008-5081 EXPLOITDB c VERIFIED
Avahi < 0.6.23 - Resource Management Error
The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) via a crafted mDNS packet with a source port of 0, which triggers an assertion failure.
by Jon Oberheide
EIP-2026-102652 EXPLOITDB c VERIFIED
Linux Kernel 2.6.27.7-generic/2.6.18/2.6.24-1 - Local Denial of Service
by Adurit-T
CVE-2008-5079 EXPLOITDB c VERIFIED
Linux Kernel < 2.6.27.8 - Resource Management Error
net/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier allows local users to cause a denial of service (kernel infinite loop) by making two calls to svc_listen for the same socket, and then reading a /proc/net/atm/*vc file, related to corruption of the vcc table.
by Jon Oberheide
CVE-2008-5314 EXPLOITDB c VERIFIED
ClamAV <0.94.2 - DoS
Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted JPEG file, related to the cli_check_jpeg_exploit, jpeg_check_photoshop, and jpeg_check_photoshop_8bim functions.
by ilja van sprundel
EIP-2026-102942 EXPLOITDB c VERIFIED
Oracle Database Vault - 'ptrace(2)' Local Privilege Escalation
by Jakub Wartak
CVE-2008-5229 EXPLOITDB c VERIFIED
Microsoft Windows Vista Gold & SP1 - Buffer Overflow
Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allows local users in the Network Configuration Operator group to gain privileges or cause a denial of service (system crash) via a large invalid PrefixLength to the CreateIpForwardEntry2 method, as demonstrated by a "route add" command. NOTE: this issue might not cross privilege boundaries.
by Marius Wachtler
CVE-2008-5297 EXPLOITDB c VERIFIED
No-IP DUC <2.1.7 - RCE
Buffer overflow in No-IP DUC 2.1.7 and earlier allows remote HTTP servers to execute arbitrary code via a crafted response to a DNS update request, related to a missing length check in the GetNextLine function.
by XenoMuta
CVE-2008-4250 EXPLOITDB c VERIFIED
Microsoft Windows 2000 - Code Injection
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
by Polymorphours
EIP-2026-102661 EXPLOITDB c VERIFIED
Linux Kernel < 2.4.36.9/2.6.27.5 - Unix Sockets Local Kernel Panic (Denial of Service)
by Andrea Bittau
CVE-2008-4210 EXPLOITDB c VERIFIED
Linux Kernel < 2.6.21.7 - Access Control
fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a file, which allows local users to gain the privileges of a different group, and obtain sensitive information or possibly have unspecified other impact, by creating an executable file in a setgid directory through the (1) truncate or (2) ftruncate function in conjunction with memory-mapped I/O.
by gat3way
CVE-2008-6829 EXPLOITDB c VERIFIED
Vicftps - Improper Input Validation
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (forward slash, backward slash, forward slash). NOTE: this might be the same issue as CVE-2008-2031.
by Alfons Luja
CVE-2008-4619 EXPLOITDB c VERIFIED
Sunos - Denial of Service
The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in program 100000 (rpcbind), related to the XDR_DECODE operation and the taddr2uaddr function. NOTE: this might be a duplicate of CVE-2007-0165.
by Federico L. Bossi Bonin
CVE-2008-4510 EXPLOITDB c VERIFIED
Microsoft Windows Vista - Resource Management Error
Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page fault and system crash) via multiple attempts to access a virtual address in a PAGE_NOACCESS memory page.
by Defsanguje
CVE-2008-4451 EXPLOITDB c VERIFIED
Eset Software System Analyzer Tool - Code Injection
The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via a certain METHOD_NEITHER IOCTL request to \Device\esiasdrv that overwrites a pointer.
by NT Internals
EIP-2026-118963 EXPLOITDB c VERIFIED
Nokia PC Suite 7.0 - Remote Buffer Overflow
by Ciph3r
EIP-2026-118399 EXPLOITDB c VERIFIED
DATAC RealWin SCADA Server 2.0 - Remote Stack Buffer Overflow
by Ruben Santamarta
EIP-2026-115587 EXPLOITDB c VERIFIED
Mass Downloader - Malformed Executable Denial of Service
by Ciph3r
CVE-2008-4362 EXPLOITDB c VERIFIED
Deslock - Resource Management Error
The Virtual Token driver (vdlptokn.sys) 1.0.2.43 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) via a crafted IOCTL request to \Device\DLPTokenWalter0.
by NT Internals
CVE-2008-4363 EXPLOITDB c VERIFIED
Deslock - Improper Input Validation
DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially execute arbitrary code via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device that overwrites a pointer, probably related to use of the ProbeForRead function when ProbeForWrite was intended.
by mu-b
CVE-2008-1141 EXPLOITDB c VERIFIED
DLMFENC.sys <1.0.0.26 - DoS
Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kernel memory consumption) via a series of DLMFENC_IOCTL requests to \\.\DLKPFSD_Device that allocate "link list structures."
by mu-b