Exploitdb Exploits

3,138 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-115432 EXPLOITDB c VERIFIED
Impressions Games Lords of the Realm III - Nickname Remote Denial of Service
by Luigi Auriemma
CVE-2004-1688 EXPLOITDB c VERIFIED
Pigeon Server <= 3.02.0143 - Denial of Service via Long Login Name
Pigeon Server 3.02.0143 and earlier allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a long login name sent to port 3103.
by Luigi Auriemma
EIP-2026-103008 EXPLOITDB c VERIFIED
Sudo 1.6.8 - Information Disclosure
by Rosiello Security
CVE-2004-1546 EXPLOITDB c VERIFIED
MDaemon 6.5.1 - Denial of Service via Long SAML/SOML/SEND/MAIL or LIST Command
Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST command to the IMAP server.
by D_BuG
CVE-2004-1675 EXPLOITDB c VERIFIED
Serv-U File Server 4.x-5.x - Denial of Service via STOU Command with MS-DOS Device Name
Serv-U FTP server 4.x and 5.x allows remote attackers to cause a denial of service (application crash) via a STORE UNIQUE (STOU) command with an MS-DOS device name argument such as (1) COM1, (2) LPT1, (3) PRN, or (4) AUX.
by str0ke
CVE-2004-1439 EXPLOITDB c VERIFIED
BlackJumboDog 3.x - Remote Code Execution via Long FTP Commands
Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1) USER, (2) PASS, (3) RETR,(4) CWD, (5) XMKD, and (6) XRMD.
by Delikon
CVE-2004-1705 EXPLOITDB c VERIFIED
Citadel/UX <= 6.23 - Denial of Service via Long Username
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
by Nebunu
CVE-2004-1666 EXPLOITDB c VERIFIED
Trillian 0.74i - Remote Code Execution via MSN Module Buffer Overflow
Buffer overflow in the MSN module in Trillian 0.74i allows remote MSN servers to execute arbitrary code via a long string that ends in a newline character.
by Komrade
EIP-2026-118351 EXPLOITDB c VERIFIED
Cerulean Studios Trillian Client 0.74 MSN Module - Remote Buffer Overflow
by Komrade
CVE-2004-1664 EXPLOITDB c VERIFIED
Call of Duty <= 1.4 - Denial of Service via Large Query or Reply Packet
Call of Duty 1.4 and earlier allows remote attackers to cause a denial of service (game end) via a large (1) query or (2) reply packet, which is not properly handled by the buffer overflow protection mechanism. NOTE: this issue might overlap CVE-2005-0430.
by Luigi Auriemma
CVE-2004-0636 EXPLOITDB c VERIFIED
AOL Instant Messenger <5.5.3595 - RCE
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.
by John Bissell
CVE-2004-0777 EXPLOITDB c VERIFIED
Courier-IMAP 1.6.0-2.2.1 and 3.x-3.0.3 - Remote Code Execution via Format String in auth_debug
Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.
by ktha
CVE-2004-1641 EXPLOITDB c VERIFIED
Titan FTP Server 3.21 - Denial of Service via Long FTP Command
Heap-based buffer overflow in Titan FTP 3.21 and earlier allows remote attackers to cause a denial of service (crash) via a long FTP command such as (1) CWD, (2) STAT, or (3) LIST.
by lion
CVE-2004-1642 EXPLOITDB c VERIFIED
WFTPD Pro Server 3.21 - Authenticated Denial of Service via Long MLIST Commands
WFTPD Pro Server 3.21 allows remote authenticated users to cause a denial of service (crash) via a series of long MLIST commands.
by lion
CVE-2004-1751 EXPLOITDB c VERIFIED
Ground Control II: Operation Exodus - Denial of Service via Large Packet
Ground Control II: Operation Exodus 1.0.0.7 and earlier allows remote servers to cause a denial of service (client or server crash) via a large packet, which generates a "Message too long" socket error that is treated as a critical error.
by Luigi Auriemma
EIP-2026-115034 EXPLOITDB c VERIFIED
CesarFTP Server - Long Command Denial of Service
by lion
EIP-2026-102813 EXPLOITDB c VERIFIED
Debian bsdmainutils 6.0.14 - Calendar Information Disclosure
by Steven Van Acker
CVE-2004-1650 EXPLOITDB c VERIFIED
D-Link DCS-900 Internet Camera - Unauthenticated IP Address Change via UDP Broadcast
D-Link DCS-900 Internet Camera listens on UDP port 62976 for an IP address, which allows remote attackers to change the IP address of the camera via a UDP broadcast packet.
by anonymous
CVE-2004-1705 EXPLOITDB c VERIFIED
Citadel/UX <= 6.23 - Denial of Service via Long Username
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
by Nebunu
CVE-2004-1752 EXPLOITDB c VERIFIED
Gaucho 1.4 Build 145 - Buffer Overflow
Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email with a long Content-Type header.
by Tan Chew Keong
CVE-2004-1745 EXPLOITDB c VERIFIED
Painkiller 1.3.1 - Buffer Overflow via Long Password
Buffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long password.
by Luigi Auriemma
CVE-2004-0820 EXPLOITDB c VERIFIED
Winamp < 5.0.4 - Remote Code Execution via Malicious Skin File
Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.
by Petrol Designs
CVE-2004-1748 EXPLOITDB c VERIFIED
sysinternals regmon < 6.11 - Denial of Service via Invalid Hook Function Pointers
NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.
by Next Generation Security
EIP-2026-116174 EXPLOITDB c VERIFIED
RealVNC Server 4.0 - Remote Denial of Service
by Uz4yh4N
EIP-2026-103128 EXPLOITDB c VERIFIED
Hafiye 1.0 - Remote Terminal Escape Sequence Injection
by Serkan Akpolat