Exploitdb Exploits

3,138 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-4927 EXPLOITDB c VERIFIED
Symantec AntiVirus <20061.3.0.12 - Privilege Escalation
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system addresses using a crafted Irp to the IOCTL functions (1) 0x222AD3, (2) 0x222AD7, and (3) 0x222ADB.
by Ruben Santamarta
CVE-2006-3824 EXPLOITDB c VERIFIED
Sun Solaris - Kernel Memory Exposure via sysinfo System Call
systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo system call, which causes a -1 argument to be used by the copyout function. NOTE: this issue has been referred to as an integer overflow, but it is probably more like a signedness error or integer underflow.
by Marco Ivaldi
CVE-2006-4318 EXPLOITDB c VERIFIED
WFTPD Server 3.23 - Remote Code Execution via Long SIZE Command
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
by h07
CVE-2006-3439 EXPLOITDB c VERIFIED
Microsoft Windows <2003 - Buffer Overflow
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers, including anonymous users, to execute arbitrary code via a crafted RPC message, a different vulnerability than CVE-2006-1314.
by Preddy
CVE-2006-7210 EXPLOITDB c VERIFIED
Microsoft Windows 2000, XP, and Server 2003 - Denial of Service via Crafted PNG IHDR Block
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.
by vegas78
CVE-2006-7210 EXPLOITDB c VERIFIED
Microsoft Windows 2000, XP, and Server 2003 - Denial of Service via Crafted PNG IHDR Block
Microsoft Windows 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (cpu consumption) via a PNG image with crafted (1) Width and (2) Height values in the IHDR block.
by Preddy
EIP-2026-103607 EXPLOITDB c VERIFIED
Opera 9 - IRC Client Remote Denial of Service
by Preddy
CVE-2006-4192 EXPLOITDB c VERIFIED
MODPlug Tracker < 1.17.02.43 - Buffer Overflow via Crafted ITP and AMF Files
Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier, as used in GStreamer and possibly other products, allow user-assisted remote attackers to execute arbitrary code via (1) long strings in ITP files used by the CSoundFile::ReadITProject function in soundlib/Load_it.cpp and (2) crafted modules used by the CSoundFile::ReadSample function in soundlib/Sndfile.cpp, as demonstrated by crafted AMF files.
by Luigi Auriemma
CVE-2006-4132 EXPLOITDB c VERIFIED
ArcSoft MMS Composer < 1.5.5.6 - Denial of Service via WAPPush Messages
ArcSoft MMS Composer 1.5.5.6 and possibly earlier, and 2.0.0.13 and possibly earlier, allow remote attackers to cause a denial of service (resource exhaustion and application crash) via WAPPush messages to UDP port UDP 2948.
by Collin Mulliner
CVE-2006-4131 EXPLOITDB c VERIFIED
ArcSoft MMS Composer < 1.5.5.6 - Buffer Overflow via Crafted MMS Messages
Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted MMS (Multimedia Messaging Service) messages that trigger the overflows in the (1) M-Notification.ind, (2) M-Retrieve.conf (Header and Body), or (3) SMIL parsers.
by Collin Mulliner
EIP-2026-118477 EXPLOITDB c VERIFIED
EasyCafe 2.1/2.2 - Security Restriction Bypass
by Mobin Yazarlou
CVE-2006-4024 EXPLOITDB c VERIFIED
Festalon 0.5.0-0.5.5 - Denial of Service and Possible Remote Code Execution via Negative LoadAddr in HES File
The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative LoadAddr value in a HES file, which is used as an offset in a memcpy operation and leads to a buffer underflow.
by Luigi Auriemma
CVE-2006-4068 EXPLOITDB c VERIFIED
pswd.js - Weak Hashing Scheme Enabling Offline Brute Force Attacks
The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing scheme that creates a large number of collisions, which makes it easier for remote attackers to conduct offline brute force attacks. NOTE: this script might also allow attackers to generate the server-side "secret" URL without determining the original password, but this possibility was not discussed by the original researcher.
by Gianstefano Monni
CVE-2006-4046 EXPLOITDB c VERIFIED
Open Cubic Player < 0.1.10_rc5 - Remote Code Execution via Crafted .S3M, .IT, .ULT, or .AMS File
Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier on Linux/BSD, allow remote attackers to execute arbitrary code via (1) a large .S3M file handled by the mpLoadS3M function, (2) a crafted .IT file handled by the itplayerclass::module::load function, (3) a crafted .ULT file handled by the mpLoadULT function, or (4) a crafted .AMS file handled by the mpLoadAMS function.
by Luigi Auriemma
CVE-2006-4006 EXPLOITDB c VERIFIED
BomberClone <= 0.11.6 - Exposure of Sensitive Information via Packet Data Size Mismanagement
The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.
by Luigi Auriemma
CVE-2006-3931 EXPLOITDB c VERIFIED
Midirecord 2.0 - Local Buffer Overflow via Long Command Line Argument
Buffer overflow in the daemon function in midirecord.cc in Tuomas Airaksinen Midirecord 2.0 allows local users to execute arbitrary code via a long command line argument (filename). NOTE: This may not be a vulnerability if Midirecord is not installed setuid.
by Dedi Dwianto
CVE-2006-3815 EXPLOITDB c VERIFIED
heartbeat < 2.0.6 - Denial of Service via Shared Memory Permissions
heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.
by anonymous
CVE-2006-3879 EXPLOITDB c VERIFIED
Mikmod Sound System 3.2.2 - Denial of Service via GT2 Module XCOM Chunk Comment Length
Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial of service via a GRAOUMF TRACKER (GT2) module file with a large (0xffffffff) comment length value in an XCOM chunk.
by Luigi Auriemma
CVE-2006-3880 EXPLOITDB c VERIFIED
Microsoft Windows 2000 and 2003 Server - Denial of Service via Malformed TCP Packets on Port 135
Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation.
by J. Oquendo
CVE-2006-3824 EXPLOITDB c VERIFIED
Sun Solaris - Kernel Memory Exposure via sysinfo System Call
systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo system call, which causes a -1 argument to be used by the copyout function. NOTE: this issue has been referred to as an integer overflow, but it is probably more like a signedness error or integer underflow.
by prdelka
CVE-2006-3814 EXPLOITDB c VERIFIED
cheese_tracker < 0.9.9 - Buffer Overflow in Loader_XM::load_instrument_internal
Buffer overflow in the Loader_XM::load_instrument_internal function in loader_xm.cpp for Cheese Tracker 0.9.9 and earlier allows user-assisted attackers to execute arbitrary code via a crafted file with a large amount of extra data.
by Luigi Auriemma
CVE-2006-0026 EXPLOITDB c VERIFIED
Internet Information Services 5.0-6.0 - Buffer Overflow via Crafted Active Server Pages
Buffer overflow in Microsoft Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows local and possibly remote attackers to execute arbitrary code via crafted Active Server Pages (ASP).
by cocoruder
CVE-2006-3942 EXPLOITDB c VERIFIED
Microsoft Windows NT 4.0, 2000, XP, Server 2003 - Denial of Service via Malformed SMB Transaction String
The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research; the vulnerability is not associated with a mailslot.
by cocoruder
CVE-2006-3668 EXPLOITDB c VERIFIED
Dynamic Universal Music Bibliotheque < 0.9.3 - Heap-Based Buffer Overflow via IT File Envelope Nodes
Heap-based buffer overflow in the it_read_envelope function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of 20060716, including libdumb, allows user-assisted attackers to execute arbitrary code via a ".it" (Impulse Tracker) file with an envelope with a large number of nodes.
by Luigi Auriemma
CVE-2006-3845 EXPLOITDB c VERIFIED
WinRAR 3.00-3.60 beta 6 - Stack-based Buffer Overflow via Long Filename in LHA Archive
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.
by Ryan Smith