Exploitdb Exploits

3,138 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-2057 EXPLOITDB c VERIFIED
airodump-ng 0.7 - Remote Code Execution via Crafted 802.11 Authentication Packets
Stack-based buffer overflow in aircrack-ng airodump-ng 0.7 allows remote attackers to execute arbitrary code via crafted 802.11 authentication packets.
by Jonathan So
CVE-2007-0038 EXPLOITDB c VERIFIED
Microsoft Windows 2000 SP4 through Vista - Remote Code Execution via Animated Cursor RIFF File
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.
by Breno Silva Pinto
CVE-2007-1867 EXPLOITDB c VERIFIED
IrfanView 3.99 - Buffer Overflow via Crafted ANI File
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.
by Breno Silva Pinto
CVE-2007-1215 EXPLOITDB c VERIFIED
Microsoft Windows - Buffer Overflow
Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and SP2; and Vista allows local users to gain privileges via certain "color-related parameters" in crafted images.
by Ivanlef0u
CVE-2007-0038 EXPLOITDB c VERIFIED
Microsoft Windows 2000 SP4 through Vista - Remote Code Execution via Animated Cursor RIFF File
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.
by Marsu
CVE-2007-1001 EXPLOITDB c VERIFIED
PHP 4.0.0-4.4.6 and 5.0.0-5.2.1 - Remote Code Execution via WBMP Image Integer Overflow
Multiple integer overflows in the (1) createwbmp and (2) readwbmp functions in wbmp.c in the GD library (libgd) in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allow context-dependent attackers to execute arbitrary code via Wireless Bitmap (WBMP) images with large width or height values.
by Ivan Fratric
CVE-2006-4250 EXPLOITDB c VERIFIED
Debian Linux - Buffer Overflow via -H Flag
Buffer overflow in man and mandb (man-db) 2.4.3 and earlier allows local users to execute arbitrary code via crafted arguments to the -H flag.
by Daniel Roethlisberger
CVE-2007-1948 EXPLOITDB c VERIFIED
IrfanView 3.99 - Buffer Overflow via Crafted BMP Image
Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via the (1) xoffset or (2) yoffset RLE command, or (3) large non-RLE encoded blocks in a crafted BMP image, as demonstrated by rle8of3.bmp and rle8of4.bmp.
by Ivan Fratric
CVE-2007-1942 EXPLOITDB c VERIFIED
FastStone Image Viewer 2.9 - Denial of Service and Possible Remote Code Execution via Crafted BMP Image
Integer overflow in FastStone Image Viewer 2.9 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted BMP image, as demonstrated by wh3intof.bmp and wh4intof.bmp.
by Ivan Fratric
CVE-2007-1943 EXPLOITDB c VERIFIED
ACDSee Photo Manager 9.0 - Integer Overflow and Remote Code Execution via Crafted BMP Image
Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via large width image sizes in a crafted BMP image, as demonstrated by w3intof.bmp and w4intof.bmp.
by Ivan Fratric
CVE-2007-1765 EXPLOITDB c VERIFIED
Microsoft Windows 2000 and 2003 Server - Remote Code Execution via Malformed ANI File
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malformed ANI file, which results in memory corruption when processing cursors, animated cursors, and icons, a similar issue to CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this issue might be a duplicate of CVE-2007-0038; if so, then use CVE-2007-0038 instead of this identifier.
by devcode
CVE-2007-1511 EXPLOITDB c VERIFIED
FrontBase Relational Database Server < 4.2.7 - Authenticated Buffer Overflow via CREATE PROCEDURE
Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privileges for creating a stored procedure, to execute arbitrary code via a CREATE PROCEDURE request with a long procedure name.
by Heretic2
CVE-2007-0038 EXPLOITDB c VERIFIED
Microsoft Windows 2000 SP4 through Vista - Remote Code Execution via Animated Cursor RIFF File
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a large length value in the second (or later) anih block of a RIFF .ANI, cur, or .ico file, which results in memory corruption when processing cursors, animated cursors, and icons, a variant of CVE-2005-0416, as originally demonstrated using Internet Explorer 6 and 7. NOTE: this might be a duplicate of CVE-2007-1765; if so, then CVE-2007-0038 should be preferred.
by Marsu
CVE-2007-1867 EXPLOITDB c VERIFIED
IrfanView 3.99 - Buffer Overflow via Crafted ANI File
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI) file.
by Marsu
EIP-2026-117354 EXPLOITDB c VERIFIED
Ipswitch WS_FTP 5.05 - Server Manager Local Site Buffer Overflow
by Marsu
CVE-2005-1255 EXPLOITDB c VERIFIED
Ipswitch IMail < 8.2 Hotfix 2 - Remote Code Execution via IMAP LOGIN Command
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins with a special character.
by Heretic2
CVE-2007-1793 EXPLOITDB c VERIFIED
Symantec Norton Personal Firewall 9.1.0.33/9.1.1.7 DoS via NtCreateMutant/NtOpenEvent
SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (crash) or possibly execute arbitrary code via crafted arguments to the (1) NtCreateMutant and (2) NtOpenEvent functions. NOTE: it was later reported that Norton Internet Security 2008 15.0.0.60, and possibly other versions back to 2006, are also affected.
by David Matousek
CVE-2007-1866 EXPLOITDB c VERIFIED
dproxy dproxy-nexgen - Stack-based Buffer Overflow in dns_decode_reverse_name
Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attackers to execute arbitrary code by sending a crafted packet to port 53/udp, a different issue than CVE-2007-1465.
by mu-b
CVE-2007-1735 EXPLOITDB c VERIFIED
Corel WordPerfect Office X3 13.0.0.565 - Stack-based Buffer Overflow via Long PRS Name
Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute arbitrary code via a long printer selection (PRS) name in a Wordperfect document.
by Jonathan So
CVE-2007-1734 EXPLOITDB c VERIFIED
Linux Kernel 2.6.20 and later - Denial of Service via DCCP Getsockopt Optlen Bounds Check
The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of service (oops), a related issue to CVE-2007-1730.
by Robert Swiecki
CVE-2007-1734 EXPLOITDB c VERIFIED
Linux Kernel 2.6.20 and later - Denial of Service via DCCP Getsockopt Optlen Bounds Check
The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of service (oops), a related issue to CVE-2007-1730.
by Robert Swiecki
CVE-2007-1388 EXPLOITDB c VERIFIED
Linux Kernel < 2.6.19.7 - Denial of Service via IPV6_RTHDR Setsockopt NULL Pointer Dereference
The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions, allows local users to cause a denial of service (oops) by calling setsockopt with the IPV6_RTHDR option name and possibly a zero option length or invalid option value, which triggers a NULL pointer dereference.
by Joey Mengele
CVE-2007-1719 EXPLOITDB c VERIFIED
mcweject - Buffer Overflow via Long Command Line Argument
Buffer overflow in eject.c in Jason W. Bacon mcweject 0.9 on FreeBSD, and possibly other versions, allows local users to execute arbitrary code via a long command line argument, possibly involving the device name.
by harry
CVE-2007-1567 EXPLOITDB c VERIFIED
War FTP Daemon < 1.65 - Stack-Based Buffer Overflow
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same issue as CVE-1999-0256, CVE-2000-0131, or CVE-2006-2171, but due to Immunity's lack of details, this cannot be certain.
by niXel
CVE-2007-1644 EXPLOITDB c VERIFIED
Microsoft Windows DNS Server - Unauthenticated DNS Record Manipulation via Dynamic Update Mechanism
The dynamic DNS update mechanism in the DNS Server service on Microsoft Windows does not properly authenticate clients in certain deployments or configurations, which allows remote attackers to change DNS records for a web proxy server and conduct man-in-the-middle (MITM) attacks on web traffic, conduct pharming attacks by poisoning DNS records, and cause a denial of service (erroneous name resolution).
by Andres Tarasco