Exploitdb Exploits

3,149 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-102789 EXPLOITDB c VERIFIED
BitchX 1.0c19 - Local Privilege Escalation
by Sha0
CVE-2004-1558 EXPLOITDB c VERIFIED
Ypops - Buffer Overflow
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) POP3 USER command or (2) SMTP request.
by Diabolic Crab
CVE-2004-0940 EXPLOITDB HIGH c VERIFIED
Apache <1.3.32 - Buffer Overflow
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
by xCrZx
CVSS 7.8
CVE-2004-1602 EXPLOITDB c VERIFIED
Proftpd < 1.2.10 - Information Disclosure
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.
by Leon Juranic
CVE-2004-1898 EXPLOITDB c VERIFIED
Tildeslash Monit - Buffer Overflow
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.
by rtk
CVE-2004-1558 EXPLOITDB c VERIFIED
Ypops - Buffer Overflow
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) POP3 USER command or (2) SMTP request.
by class101
CVE-2004-2176 EXPLOITDB c VERIFIED
Microsoft Windows XP SP2 - Auth Bypass
The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which allows local users to use sessmgr.exe to create a local listening port that bypasses the ICF access controls.
by americanidiot
CVE-2004-1561 EXPLOITDB c VERIFIED
Icecast - Buffer Overflow
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.
by K-C0d3r
CVE-2004-1587 EXPLOITDB c VERIFIED
Monolith Productions Alien Versus Predator - Buffer Overflow
Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier, (3) No one lives forever 1.004 and earlier and (4) Shogo 2.2 and earlier allows remote attackers to cause a denial of service (application crash) via a long secure Gamespy query.
by Luigi Auriemma
CVE-2004-1561 EXPLOITDB c VERIFIED
Icecast - Buffer Overflow
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers.
by Delikon
CVE-2004-1560 EXPLOITDB c VERIFIED
Microsoft Sql Server - Buffer Overflow
Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long request to TCP port 1433, possibly triggering a buffer overflow.
by securma massine
CVE-2004-0964 EXPLOITDB c VERIFIED
Zinf <2.2.1 - RCE
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.
by Delikon
EIP-2026-118131 EXPLOITDB c VERIFIED
WinRAR 1.0 - Local Buffer Overflow
by ATmaCA
EIP-2026-115769 EXPLOITDB c VERIFIED
Microsoft SQL Server 7.0 - Remote Denial of Service (2)
by Sebastien Tricaud
EIP-2026-115768 EXPLOITDB c VERIFIED
Microsoft SQL Server 7.0 - Remote Denial of Service (1)
by securma massine
CVE-2004-0200 EXPLOITDB c VERIFIED
Microsoft .net Framework - Buffer Overflow
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
by M4Z3R
CVE-2005-4316 EXPLOITDB c VERIFIED
HP-UX - DoS
HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.
by Ken Hollis
CVE-2005-4316 EXPLOITDB c VERIFIED
HP-UX - DoS
HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.
by Ken Hollis
CVE-2005-4316 EXPLOITDB c VERIFIED
HP-UX - DoS
HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.
by Coolio
CVE-2005-4316 EXPLOITDB c VERIFIED
HP-UX - DoS
HP-UX B.11.00, B.11.04, B.11.11, and B.11.23 allows remote attackers to cause a denial of service via a "Rose Attack" that involves sending a subset of small IP fragments that do not form a complete, larger packet.
by Coolio
CVE-2004-2517 EXPLOITDB c VERIFIED
myServer 0.7.1 - DoS
myServer 0.7.1 allows remote attackers to cause a denial of service (crash) via a long HTTP POST request in a View=Logon operation to index.html.
by Tom Ferris
CVE-2004-0200 EXPLOITDB c VERIFIED
Microsoft .net Framework - Buffer Overflow
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
by John Bissell
CVE-2004-0200 EXPLOITDB c VERIFIED
Microsoft .net Framework - Buffer Overflow
Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows remote attackers to execute arbitrary code via a JPEG image with a small JPEG COM field length that is normalized to a large integer length before a memory copy operation.
by ATmaCA
EIP-2026-102864 EXPLOITDB c VERIFIED
GNU Sharutils 4.2.1 - Local Format String
by n4rk0tix
CVE-2004-1698 EXPLOITDB c VERIFIED
Leadmind Popmessenger - Denial of Service
The Base64 function in PopMessenger 1.60 (before 20 Sep 2004) and earlier allows remote attackers to cause a denial of service (application crash) via invalid characters in a message, which causes several alert dialogs to be displayed and leads to a crash.
by Luigi Auriemma