Exploitdb Exploits

3,149 exploits tracked across all sources.

Sort: Activity Stars
CVE-2008-4363 EXPLOITDB c VERIFIED
Deslock - Improper Input Validation
DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially execute arbitrary code via a certain DLMFENC_IOCTL request to \\.\DLKPFSD_Device that overwrites a pointer, probably related to use of the ProbeForRead function when ProbeForWrite was intended.
by mu-b
CVE-2008-2032 EXPLOITDB c VERIFIED
Acritum Femitter Server 1.03 - DoS
The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending multiple crafted RETR commands. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by LiquidWorm
CVE-2008-3889 EXPLOITDB c VERIFIED
Postfix <2.4.9, 2.5 <2.5.5, 2.6 <2.6-20080902 - DoS
Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown or exit) via a crafted command, as demonstrated by a command in a .forward file.
by Albert Sellares
CVE-2008-4042 EXPLOITDB c VERIFIED
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-3889. Reason: This candidate is a duplicate of CVE-2008-3889. Notes: All CVE users should reference CVE-2008-3889 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
by Albert Sellares
CVE-2008-4136 EXPLOITDB c VERIFIED
Michael Roth Software Pftp - Improper Input Validation
Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash) via multiple RETR commands, possibly involving long filenames.
by Shinnok
CVE-2008-3727 EXPLOITDB c VERIFIED
MicroWorld Technologies MailScan <5.6.a - Path Traversal
Directory traversal vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
by SlaYeR
CVE-2008-6976 EXPLOITDB c VERIFIED
Mikrotik Routeros < 2.9.51 - Improper Input Validation
MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.
by ShadOS
CVE-2008-0964 EXPLOITDB c VERIFIED
SUN Opensolaris - Memory Corruption
Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o option is omitted, allow remote attackers to execute arbitrary code via a crafted SMB packet.
by Andi
CVE-2008-3360 EXPLOITDB c VERIFIED
IntelliTamper 2.0.7 - RCE
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code via a long URL in the HREF attribute of an A element, a different vulnerability than CVE-2006-2494.
by kralor
CVE-2008-3361 EXPLOITDB c VERIFIED
IntelliTamper 2.07 - Buffer Overflow
Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Server header.
by Wojciech Pawlikowski
CVE-2008-3583 EXPLOITDB c VERIFIED
IntelliTamper 2.07 - RCE
Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long URL in the SRC attribute of an IMG element. NOTE: this might be related to CVE-2008-3360. NOTE: it was later reported that 2.08 Beta 4 is also affected.
by r0ut3r
CVE-2007-2363 EXPLOITDB c VERIFIED
IrfanView <4.00 - RCE
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.
by fl0 fl0w
CVE-2010-0437 EXPLOITDB c VERIFIED
Linux Kernel < 2.6.26.8 - Denial of Service
The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via unknown vectors.
by Rémi Denis-Courmont
CVE-2007-2586 EXPLOITDB c VERIFIED
Cisco IOS <12.4 - RCE
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, and have other impact including reading startup-config, as demonstrated by a crafted MKD command that involves access to a VTY device and overflows a buffer, aka bug ID CSCek55259.
by Andy Davis
CVE-2008-1447 EXPLOITDB MEDIUM c VERIFIED
BIND 8-9 <9.5.0-P1 - RCE
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2; and other implementations allow remote attackers to spoof DNS traffic via a birthday attack that uses in-bailiwick referrals to conduct cache poisoning against recursive resolvers, related to insufficient randomness of DNS transaction IDs and source ports, aka "DNS Insufficient Socket Entropy Vulnerability" or "the Kaminsky bug."
by Marc Bevand
CVSS 6.8
CVE-2008-4194 EXPLOITDB c VERIFIED
Pdnsd < 1.2.6-par - Resource Management Error
The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of service (daemon crash) via a long DNS reply with many entries in the answer section, related to a "dangling pointer bug."
by Marc Bevand
CVE-2008-2463 EXPLOITDB c VERIFIED
Microsoft Office Snapshot Viewer Activex - Code Injection
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snapshot Viewer and Microsoft Office Access 2000 through 2003, allows remote attackers to download arbitrary files to a client machine via a crafted HTML document or e-mail message, probably involving use of the SnapshotPath and CompressedPath properties and the PrintSnapshot method. NOTE: this can be leveraged for code execution by writing to a Startup folder.
by callAX
CVE-2008-3360 EXPLOITDB c VERIFIED
IntelliTamper 2.0.7 - RCE
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code via a long URL in the HREF attribute of an A element, a different vulnerability than CVE-2006-2494.
by r0ut3r
CVE-2008-3286 EXPLOITDB c VERIFIED
SWAT 4 <1.1 - DoS
SWAT 4 1.1 and earlier allows remote attackers to cause a denial of service (daemon crash) via a (1) VERIFYCONTENT or (2) GAMECONFIG command sent to the server before user session initialization, which triggers a NULL pointer dereference; or (3) a GAMESPYRESPONSE command followed by a long RS string.
by Luigi Auriemma
CVE-2008-3269 EXPLOITDB c VERIFIED
WinSoftMagic WRPC <2008 - DoS
WRPCServer.exe in WinSoftMagic WinRemotePC (WRPC) Lite 2008 and Full 2008 allows remote attackers to cause a denial of service (CPU consumption) via a crafted packet to TCP port 4321.
by Shinnok
CVE-2008-3182 EXPLOITDB c VERIFIED
Download Accelerator Plus <8.6.6.3 - Buffer Overflow
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allows user-assisted remote attackers to execute arbitrary code via an M3U (.m3u) file containing a long MP3 URL.
by Shinnok
EIP-2026-104547 EXPLOITDB c VERIFIED
OpenBSD 4.0 - 'vga' Local Privilege Escalation
by lul-disclosure inc.
CVE-2008-2427 EXPLOITDB c VERIFIED
Pagesperso-orange Gfl SDK - Memory Corruption
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.
by Shinnok
CVE-2008-2365 EXPLOITDB c VERIFIED
Linux Kernel - Race Condition
Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptrace_may_attach() check" and "race around &dead_engine_ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this issue might only affect kernel versions before 2.6.16.x.
by Alexei Dobryanov
CVE-2008-2365 EXPLOITDB c VERIFIED
Linux Kernel - Race Condition
Race condition in the ptrace and utrace support in the Linux kernel 2.6.9 through 2.6.25, as used in Red Hat Enterprise Linux (RHEL) 4, allows local users to cause a denial of service (oops) via a long series of PTRACE_ATTACH ptrace calls to another user's process that trigger a conflict between utrace_detach and report_quiescent, related to "late ptrace_may_attach() check" and "race around &dead_engine_ops setting," a different vulnerability than CVE-2007-0771 and CVE-2008-1514. NOTE: this issue might only affect kernel versions before 2.6.16.x.
by Alexei Dobryanov