C Exploits

3,628 exploits tracked across all sources.

Sort: Activity Stars
CVE-2006-6340 EXPLOITDB c VERIFIED
nVIDIA nView - Denial of Service via Long Command Line Argument
keystone.exe in nVIDIA nView allows attackers to cause a denial of service via a long command line argument. NOTE: it is not clear whether this issue crosses security boundaries. If not, then this is not a vulnerability.
by Hessam-x
CVE-2006-5854 EXPLOITDB c VERIFIED
Novell Netware Client 4.91-4.91 SP2 - Remote Code Execution via Spooler Service Buffer Overflow
Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitrary code via a long argument to the (1) EnumPrinters and (2) OpenPrinter functions.
by Andres Tarasco Acuna
EIP-2026-118185 EXPLOITDB c VERIFIED
XMPlay 3.3.0.4 - '.PLS' Local Buffer Overflow
by Greg Linares
CVE-2006-6063 EXPLOITDB c VERIFIED
XMPlay < 3.3.0.5 - Stack-Based Buffer Overflow via M3U File
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (1) FileName, and cause a crash via a long (2) DisplayName.
by Greg Linares
CVE-2006-6097 EXPLOITDB c VERIFIED
GNU tar 1.15.1-1.16 - Arbitrary File Overwrite via GNUTYPE_NAMES Symbolic Link
GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.
by Teemu Salmela
CVE-2006-6063 EXPLOITDB c VERIFIED
XMPlay < 3.3.0.5 - Stack-Based Buffer Overflow via M3U File
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via a M3U file containing a long (1) FileName, and cause a crash via a long (2) DisplayName.
by Greg Linares
EIP-2026-104546 EXPLOITDB c VERIFIED
OpenBSD 3.9/4.0 - 'ld.so' Local Environment Variable Clearing
by Mark Dowd
CVE-2006-6952 EXPLOITDB c VERIFIED
Computer Associates HIPS - Privilege Escalation
Computer Associates Host Intrusion Prevention System (HIPS) drivers (1) Core kmxstart.sys 6.5.4.31 and (2) Firewall kmxfw.sys 6.5.4.10 allow local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers.
by Ruben Santamarta
CVE-2006-6952 EXPLOITDB c VERIFIED
Computer Associates HIPS - Privilege Escalation
Computer Associates Host Intrusion Prevention System (HIPS) drivers (1) Core kmxstart.sys 6.5.4.31 and (2) Firewall kmxfw.sys 6.5.4.10 allow local users to gain privileges by using certain privileged IOCTLs to modify callback function pointers.
by Ruben Santamarta
CVE-2006-3890 EXPLOITDB c VERIFIED
Sky Software FileView ActiveX Control - Stack-Based Buffer Overflow via FilePattern Attribute
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code via a long FilePattern attribute in a WZFILEVIEW object, a different vulnerability than CVE-2006-5198.
by prdelka
CVE-2006-6884 EXPLOITDB c VERIFIED
WinZip 10.0 Build 6667 - Buffer Overflow
Buffer overflow in the WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 Build 6667 allows remote attackers to execute arbitrary code via a long argument to the CreateNewFolderFromName method, a different vulnerability than CVE-2006-5198.
by prdelka
CVE-2008-5431 EXPLOITDB c VERIFIED
Teamtek Universal FTP Server 1.0.44 - DoS
Teamtek Universal FTP Server 1.0.44 allows remote attackers to cause a denial of service via (1) a certain CWD command, (2) a long LIST command, or (3) a certain PORT command.
by Greg Linares
EIP-2026-103893 EXPLOITDB c VERIFIED
Digipass Go3 - Insecure Encryption
by faypou
CVE-2006-5745 EXPLOITDB c VERIFIED
Microsoft XML Core Services 4.0 - RCE
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML Core Services 4.0 on Windows, when accessed by Internet Explorer, allows remote attackers to execute arbitrary code via crafted arguments that lead to memory corruption, a different vulnerability than CVE-2006-4685. NOTE: some of these details are obtained from third party information.
by M03
CVE-2006-5836 EXPLOITDB c VERIFIED
Darwin Kernel 8.8.1 - Denial of Service via fpathconf Syscall
The fpathconf syscall function in bsd/kern/kern_descrip.c in the Darwin kernel (XNU) 8.8.1 in Apple Mac OS X allows local users to cause a denial of service (kernel panic) and possibly execute arbitrary code via a file descriptor with an unrecognized file type.
by ilja van sprundel
CVE-2006-5567 EXPLOITDB c VERIFIED
Nullsoft WinAmp - Heap-Based Buffer Overflow via Ultravox Protocol Handler or Lyrics3 Tags
Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to the Ultravox protocol handler or (2) unspecified Lyrics3 tags.
by cocoruder
CVE-2006-5715 EXPLOITDB c VERIFIED
Easy File Sharing (EFS) Easy Address Book 1.2 - Info Disclosure
Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of an HTTP GET request, which accesses the alternate data stream.
by Greg Linares
EIP-2026-118969 EXPLOITDB c VERIFIED
Novell eDirectory 9.0 - 'DHost' Remote Buffer Overflow
by Expanders
CVE-2006-5714 EXPLOITDB c VERIFIED
Easy File Sharing EFS Web Server 4.0 - Info Disclosure
Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of a HTTP GET request, which accesses the alternate data stream.
by Greg Linares
CVE-2006-5478 EXPLOITDB c VERIFIED
Novell eDirectory 8.x-8.8.x - Remote Code Execution via Long HTTP Host Header or Dot in Username
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute arbitrary code via (1) a long HTTP Host header, which triggers an overflow in the BuildRedirectURL function; or vectors related to a username containing a . (dot) character in the (2) SMTP, (3) POP, (4) IMAP, (5) HTTP, or (6) Networked Messaging Application Protocol (NMAP) Netmail services.
by Expanders
CVE-2006-5551 EXPLOITDB c VERIFIED
qk_smtp < 3.0.1 - Remote Code Execution via RCPT TO Command
Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a long argument to the RCPT TO command.
by Expanders
CVE-2006-5597 EXPLOITDB c VERIFIED
MiniHTTP Web Forum & File Server PowerPack 4.0 - RCE
join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters.
by Greg Linares
CVE-2006-5552 EXPLOITDB c VERIFIED
RevilloC MailServer <= 1.21 - Remote Code Execution via Long MAIL FROM or RCPT TO Argument
Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of service (CPU consumption or application crash) or execute arbitrary code via a long argument to the (1) MAIL FROM or (2) RCPT TO command.
by Greg Linares
CVE-2006-5596 EXPLOITDB c VERIFIED
AEP Smartgate 4.3b - Directory Traversal via HTTP GET Request
Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary files via ..\ (dot dot backslash) sequences in an HTTP GET request.
by prdelka
CVE-2006-5725 EXPLOITDB c VERIFIED
AEP Smartgate SSL Server 4.3b - Directory Existence Disclosure via HTTP Status Code
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories.
by prdelka