Exploitdb Exploits

3,138 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-6199 EXPLOITDB c VERIFIED
BlazeVideo BlazeDVD Standard and Professional 5.0 - Stack-based Buffer Overflow via PLF Playlist Filename
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist.
by Greg Linares
CVE-2006-6396 EXPLOITDB c VERIFIED
BlazeVideo HDTV Player <3.5 - Buffer Overflow
Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via a long filename in a PLF playlist, a different product than CVE-2006-6199. NOTE: it was later reported that 3.5 is also affected.
by Greg Linares
CVE-2009-0450 EXPLOITDB c VERIFIED
BlazeVideo HDTV Player <3.5 - Buffer Overflow
Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code via a long string in a playlist (aka .plf) file.
by Greg Linares
CVE-2006-6251 EXPLOITDB c VERIFIED
VUPlayer < 2.44 - Remote Code Execution via Long M3U File String
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long string in an M3U file, aka an "M3U UNC Name" attack.
by Expanders
CVE-2006-6287 EXPLOITDB c VERIFIED
AtomixMP3 < 2.3 - Stack-Based Buffer Overflow via Long M3U Pathname
Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pathname in an M3U file.
by Greg Linares
CVE-2006-6173 EXPLOITDB c VERIFIED
Mac OS X < 10.4.6 - Local Buffer Overflow in shared_region_make_private_np
Buffer overflow in the shared_region_make_private_np function in vm/vm_unix.c in Mac OS X 10.4.6 and earlier allows local users to execute arbitrary code via (1) a small range count, which causes insufficient memory allocation, or (2) a large number of ranges in the shared_region_make_private_np_args parameter.
by LMH
CVE-2006-6250 EXPLOITDB c VERIFIED
Songbird Media Player < 0.2 - Denial of Service via M3U Playlist Extended ASCII Handling
Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of service (crash) via an M3U Playlist file containing extended ASCII, which causes the Unicode converter to be invoked.
by Greg Linares
CVE-2006-6261 EXPLOITDB c VERIFIED
Quintessential Player < 4.50.1.82 - Buffer Overflow via Crafted M3U, M3U-8, or PLS File
Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) M3u or (2) M3u-8 file; or a (3) crafted PLS file with a long value in the (a) NumberofEntries, (b) Length (aka Length1), (c) Filename (aka File1), (d) Title (aka Title1) field, or other unspecified fields.
by Greg Linares
CVE-2006-5864 EXPLOITDB c VERIFIED
GNU gv 3.6.2 - Stack-based Buffer Overflow via Long Comments in PostScript Headers
Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and possibly (3) PageMedia and (4) PaperSize headers. NOTE: this issue can be exploited through other products that use gv such as evince.
by K-sPecial
CVE-2006-6130 EXPLOITDB c VERIFIED
Apple Mac OS X - Denial of Service via AIOCREGLOCALZN ioctl Command
Apple Mac OS X AppleTalk allows local users to cause a denial of service (kernel panic) by calling the AIOCREGLOCALZN ioctl command with a crafted data structure on an AppleTalk socket.
by LMH
CVE-2006-6340 EXPLOITDB c VERIFIED
nVIDIA nView - Denial of Service via Long Command Line Argument
keystone.exe in nVIDIA nView allows attackers to cause a denial of service via a long command line argument. NOTE: it is not clear whether this issue crosses security boundaries. If not, then this is not a vulnerability.
by Hessam-x
CVE-2006-5854 EXPLOITDB c VERIFIED
Novell Netware Client 4.91-4.91 SP2 - Remote Code Execution via Spooler Service Buffer Overflow
Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitrary code via a long argument to the (1) EnumPrinters and (2) OpenPrinter functions.
by Andres Tarasco Acuna
EIP-2026-118185 EXPLOITDB c VERIFIED
XMPlay 3.3.0.4 - '.PLS' Local Buffer Overflow
by Greg Linares
CVE-2006-6063 EXPLOITDB c VERIFIED
XMPlay < 3.3.0.5 - Stack-Based Buffer Overflow via M3U File
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (1) FileName, and cause a crash via a long (2) DisplayName.
by Greg Linares
CVE-2006-6097 EXPLOITDB c VERIFIED
GNU tar 1.15.1-1.16 - Arbitrary File Overwrite via GNUTYPE_NAMES Symbolic Link
GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.
by Teemu Salmela
CVE-2006-6063 EXPLOITDB c VERIFIED
XMPlay < 3.3.0.5 - Stack-Based Buffer Overflow via M3U File
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (1) FileName, and cause a crash via a long (2) DisplayName.
by Greg Linares
EIP-2026-104546 EXPLOITDB c VERIFIED
OpenBSD 3.9/4.0 - 'ld.so' Local Environment Variable Clearing
by Mark Dowd
CVE-2006-6952 EXPLOITDB c VERIFIED
Computer Associates HIPS - Privilege Escalation
Computer Associates Host Intrusion Prevention System (HIPS) drivers (1) Core kmxstart.sys 6.5.4.31 and (2) Firewall kmxfw.sys 6.5.4.10 allow local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers.
by Ruben Santamarta
CVE-2006-6952 EXPLOITDB c VERIFIED
Computer Associates HIPS - Privilege Escalation
Computer Associates Host Intrusion Prevention System (HIPS) drivers (1) Core kmxstart.sys 6.5.4.31 and (2) Firewall kmxfw.sys 6.5.4.10 allow local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers.
by Ruben Santamarta
CVE-2006-3890 EXPLOITDB c VERIFIED
Sky Software FileView ActiveX Control - Stack-Based Buffer Overflow via FilePattern Attribute
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code via a long FilePattern attribute in a WZFILEVIEW object, a different vulnerability than CVE-2006-5198.
by prdelka
CVE-2006-6884 EXPLOITDB c VERIFIED
WinZip 10.0 Build 6667 - Buffer Overflow
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitrary code via a long argument to the CreateNewFolderFromName method, a different vulnerability than CVE-2006-5198.
by prdelka
CVE-2008-5431 EXPLOITDB c VERIFIED
Teamtek Universal FTP Server 1.0.44 - DoS
Teamtek Universal FTP Server 1.0.44 allows remote attackers to cause a denial of service via (1) a certain CWD command, (2) a long LIST command, or (3) a certain PORT command.
by Greg Linares
EIP-2026-103893 EXPLOITDB c VERIFIED
Digipass Go3 - Insecure Encryption
by faypou
CVE-2006-5745 EXPLOITDB c VERIFIED
Microsoft XML Core Services 4.0 - RCE
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
by M03
CVE-2006-5836 EXPLOITDB c VERIFIED
Darwin Kernel 8.8.1 - Denial of Service via fpathconf Syscall
The fpathconf syscall function in bsd/kern/kern_descrip.c in the Darwin kernel (XNU) 8.8.1 in Apple Mac OS X allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a file descriptor with an unrecognized file type.
by ilja van sprundel