C Exploits

3,624 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-118042 EXPLOITDB c VERIFIED
URL Hunter - Local Buffer Overflow (DEP Bypass)
by Ayrbyte
CVE-2012-2763 EXPLOITDB c
GIMP < 2.6.13 - Remote Code Execution via Long String in Script-Fu Server Command
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and possibly 2.6.13, allows remote attackers to execute arbitrary code via a long string in a command to the script-fu server.
by Joseph Sheridan
CVE-2011-1249 EXPLOITDB c
Microsoft Windows - Local Privilege Escalation via AFD.sys Input Validation
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
by fb1h2s
EIP-2026-103697 EXPLOITDB c VERIFIED
VideoLAN VLC Media Player 1.1.11 - '.NSV' File Denial of Service
by Dan Fosco
EIP-2026-103696 EXPLOITDB c VERIFIED
VideoLAN VLC Media Player 1.1.11 - '.EAC3' File Denial of Service
by Dan Fosco
CVE-2012-1189 EXPLOITDB c VERIFIED
TORCS < 1.3.3 and Speed Dreams - Stack-based Buffer Overflow via Long File Name in XML Configuration
Stack-based buffer overflow in modules/graphic/ssgraph/grsound.cpp in The Open Racing Car Simulator (TORCS) before 1.3.3 and Speed Dreams allows user-assisted remote attackers to execute arbitrary code via a long file name in an engine sample attribute in an xml configuration file.
by Andres Gomez & David Mora
CVE-2012-0056 EXPLOITDB c VERIFIED
Linux Kernel < 3.0.18 - Privilege Escalation via /proc/<pid>/mem Write
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.
by zx2c4
CVE-2012-0207 EXPLOITDB HIGH c
Linux Kernel < 3.2.1 - Denial of Service via IGMP Packet Divide-By-Zero
The igmp_heard_query function in net/ipv4/igmp.c in the Linux kernel before 3.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and panic) via IGMP packets.
by kingcope
CVSS 7.5
CVE-2012-0056 EXPLOITDB c VERIFIED
Linux Kernel < 3.0.18 - Privilege Escalation via /proc/<pid>/mem Write
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, which allows local users to gain privileges by modifying process memory, as demonstrated by Mempodipper.
by zx2c4
CVE-2011-4862 EXPLOITDB c VERIFIED
GNU inetutils < 1.9 - Remote Code Execution via Long Encryption Key
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the wild in December 2011.
by NighterMan & BatchDrake
CVE-2011-4620 EXPLOITDB c VERIFIED
PLIB 1.8.5 - Buffer Overflow in ulSetError Function
Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary code via vectors involving a long error message, as demonstrated by a crafted acc file for TORCS. NOTE: some of these details are obtained from third party information.
by Andrés Gómez
CVE-2011-5033 EXPLOITDB c
ConfigServer Security & Firewall < 5.43 - Stack-Based Buffer Overflow via Admin List File
Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmin server, allows local users to cause a denial of service (crash) via a long string in an admin.list file.
by FoX HaCkEr
CVE-2014-5329 EXPLOITDB HIGH c
GIGAPOD OfficeHard <3.04.03, GIGAPOD 2010/3 <3.01.02 - DoS via Apache HTTP Request Handling
GIGAPOD file servers (Appliance model and Software model) provide two web interfaces, 80/tcp and 443/tcp for user operation, and 8001/tcp for administrative operation. 8001/tcp is served by a version of Apache HTTP server containing a flaw in handling HTTP requests (CVE-2011-3192), which may lead to a denial-of-service (DoS) condition.
by Ramon de C Valle
CVSS 7.5
CVE-2011-5007 EXPLOITDB c
3S CoDeSys < 3.4 - Remote Code Execution via Long URI to CmpWebServer
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080.
by Celil Ünüver
CVE-2011-4089 EXPLOITDB c VERIFIED
bzip2 < 1.0.5 - Local Arbitrary Code Execution via Temporary File Handling
The bzexe command in bzip2 1.0.5 and earlier generates compressed executables that do not properly handle temporary files during extraction, which allows local users to execute arbitrary code by precreating a temporary directory.
by vladz
EIP-2026-115832 EXPLOITDB c
Microsoft Winows 7 - Keyboard Layout Blue Screen of Death (MS10-073)
by instruder
CVE-2011-2013 EXPLOITDB CRITICAL c VERIFIED
Microsoft Windows - Buffer Overflow
Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code by sending a sequence of crafted UDP packets to a closed port, aka "Reference Counter Overflow Vulnerability."
by anonymous
CVSS 9.8
EIP-2026-102908 EXPLOITDB c VERIFIED
Linux Kernel 3.0.4 - '/proc/interrupts' Password Length Local Information Disclosure
by Vasiliy Kulikov
EIP-2026-102796 EXPLOITDB c VERIFIED
Calibre E-Book Reader - Local Privilege Escalation (3)
by zx2c4
EIP-2026-102906 EXPLOITDB c
Linux Kernel 2.6.37-rc1 - 'serial_multiport_struct' Local Information Leak
by Todor Donev
CVE-2011-1350 EXPLOITDB c VERIFIED
Android < 2.3.6 - Information Exposure via PowerVR SGX Driver Request
The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an application that uses a crafted length parameter in a request to the pvrsrvkm device.
by Geremy Condra
CVE-2011-4613 EXPLOITDB c
X.Org X Server - Local Access Restriction Bypass via TTY Verification Flaw
The X.Org X wrapper (xserver-wrapper.c) in Debian GNU/Linux and Ubuntu Linux does not properly verify the TTY of a user who is starting X, which allows local users to bypass intended access restrictions by associating stdin with a file that is misinterpreted as the console TTY.
by vladz
CVE-2011-1485 EXPLOITDB c
Linux PolicyKit Race Condition Privilege Escalation
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.
by xi4oyu
CVE-2011-1485 EXPLOITDB c
Linux PolicyKit Race Condition Privilege Escalation
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.
by zx2c4
EIP-2026-117700 EXPLOITDB c
Norman Security Suite 8 - 'nprosec.sys' Local Privilege Escalation
by Xst3nZ