C Exploits

3,626 exploits tracked across all sources.

Sort: Activity Stars
CVE-2007-2668 EXPLOITDB c VERIFIED
webdesproxy 0.0.1 - Remote Code Execution via Long URL
Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involving the process_connection_request function in webdesproxy.c.
by Xpl017Elz
CVE-2007-2666 EXPLOITDB c VERIFIED
Notepad++ < 4.1.1 - Stack-based Buffer Overflow in LexRuby.cxx
Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, allows user-assisted remote attackers to execute arbitrary code via certain Ruby (.rb) files with long lines. NOTE: this was originally reported as a vulnerability in notepad++.
by vade79
CVE-2007-2668 EXPLOITDB c VERIFIED
webdesproxy 0.0.1 - Remote Code Execution via Long URL
Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involving the process_connection_request function in webdesproxy.c.
by vade79
EIP-2026-117143 EXPLOITDB c VERIFIED
eTrust AntiVirus Agent r8 - Local Privilege Escalation
by binagres
CVE-2007-2584 EXPLOITDB c VERIFIED
McAfee SecurityCenter <6.0.25, <7.2.147 - Buffer Overflow
Buffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCenter before 6.0.25 and 7.x before 7.2.147 allows remote attackers to execute arbitrary code via a crafted argument.
by Jambalaya
CVE-2007-2356 EXPLOITDB c VERIFIED
Gimp 2.2.14 - Stack-Based Buffer Overflow in SUNRAS Plugin via RAS File
Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file.
by Kristian Hermansen
CVE-2007-2523 EXPLOITDB c VERIFIED
CA Anti-Virus for the Enterprise r8 and Threat Manager r8 - Privilege Escalation via Task Service File Mapping
CA Anti-Virus for the Enterprise r8 and Threat Manager r8 before 20070510 use weak permissions (NULL security descriptor) for the Task Service shared file mapping, which allows local users to modify this mapping and gain privileges by triggering a stack-based buffer overflow in InoCore.dll before 8.0.448.0.
by binagres
CVE-2007-2536 EXPLOITDB c VERIFIED
PicoZip - Denial of Service via ZOO Archive Direntry Structure
PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
by Jean-Sébastien
CVE-2007-1669 EXPLOITDB c VERIFIED
AMaViS < 2.4.1 - Denial of Service via ZOO Archive Direntry Structure
zoo decoder 2.10 (zoo-2.10), as used in multiple products including (1) Barracuda Spam Firewall 3.4 and later with virusdef before 2.0.6399, (2) Spam Firewall before 3.4 20070319 with virusdef before 2.0.6399o, and (3) AMaViS 2.4.1 and earlier, allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
by Jean-Sébastien
CVE-2007-2487 EXPLOITDB c VERIFIED
AtomixMP3 - Stack-Based Buffer Overflow via Long MP3 Filename
Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3 file, a different vector than CVE-2006-6287.
by preth00nker
CVE-2007-2031 EXPLOITDB c VERIFIED
3proxy 0.5-0.5.3g - Remote Code Execution via Transparent Request Buffer Overflow
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote attackers to execute arbitrary code via crafted transparent requests.
by Xpl017Elz
CVE-2007-2031 EXPLOITDB c VERIFIED
3proxy 0.5-0.5.3g - Remote Code Execution via Transparent Request Buffer Overflow
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote attackers to execute arbitrary code via crafted transparent requests.
by vade79
CVE-2007-2498 EXPLOITDB c VERIFIED
Winamp 5.02-5.34 - Remote Code Execution via MP4 File
libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .MP4 file. NOTE: some of these details are obtained from third party information.
by Marsu
CVE-2007-2031 EXPLOITDB c VERIFIED
3proxy 0.5-0.5.3g - Remote Code Execution via Transparent Request Buffer Overflow
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote attackers to execute arbitrary code via crafted transparent requests.
by vade79
CVE-2006-2022 EXPLOITDB c VERIFIED
Fenice < 1.10 - Remote Code Execution via RTSP URL Parsing Buffer Overflow
Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote attackers to execute arbitrary code via a long URL.
by Xpl017Elz
CVE-2007-2365 EXPLOITDB c VERIFIED
Adobe GoLive 9 - Buffer Overflow via Crafted PNG File
Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.
by Marsu
CVE-2007-2366 EXPLOITDB c VERIFIED
Corel Paint Shop Pro 11.20 - Buffer Overflow via Crafted PNG File
Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a crafted .PNG file.
by Marsu
CVE-2007-2363 EXPLOITDB c VERIFIED
IrfanView < 4.00 - Buffer Overflow via Crafted IFF File
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a crafted .IFF file.
by Marsu
CVE-2007-2362 EXPLOITDB c VERIFIED
MyDNS 1.1.0 - Remote Buffer Overflow in update.c
Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and possibly execute arbitrary code via a certain update, which triggers a heap-based buffer overflow in update.c; and (2) cause a denial of service (daemon crash) via unspecified vectors that trigger an off-by-one stack-based buffer overflow in update.c.
by mu-b
CVE-2007-2356 EXPLOITDB c VERIFIED
Gimp 2.2.14 - Stack-Based Buffer Overflow in SUNRAS Plugin via RAS File
Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-assisted remote attackers to execute arbitrary code via a crafted RAS file.
by Marsu
CVE-2007-1861 EXPLOITDB c VERIFIED
Linux Kernel < 2.6.20.8 - Denial of Service via NETLINK_FIB_LOOKUP Replies
The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infinite recursion and a stack overflow.
by Alexey Kuznetsov
CVE-2007-2283 EXPLOITDB c VERIFIED
Freshdevices Freshview - Buffer Overflow
Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.
by Marsu
CVE-2007-2284 EXPLOITDB c VERIFIED
ABC-View Manager 1.42 - Buffer Overflow via Crafted PSP File
Buffer overflow in ABC-View Manager 1.42 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP file.
by Marsu
CVE-2007-2244 EXPLOITDB c VERIFIED
Adobe GoLive 9 - Buffer Overflow via Crafted BMP DIB or RLE File
Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.
by Marsu
CVE-2007-2565 EXPLOITDB c VERIFIED
Cdelia Software ImageProcessing - DoS
Cdelia Software ImageProcessing allows user-assisted remote attackers to cause a denial of service (application crash) via a crafted BMP file.
by Dr.Ninux