Exploitdb Exploits

3,149 exploits tracked across all sources.

Sort: Activity Stars
CVE-2004-0313 EXPLOITDB c VERIFIED
Psoproxy Server - Buffer Overflow
Buffer overflow in PSOProxy 0.91 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long HTTP request, as demonstrated using a long (1) GET argument or (2) method name.
by PaLbOsA
CVE-2004-0077 EXPLOITDB c VERIFIED
Linux <2.2.25, <2.4.24, <2.6.2 - Privilege Escalation
The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than CAN-2003-0985.
by Christophe Devine
CVE-2004-0286 EXPLOITDB c VERIFIED
Robotftp Server - Buffer Overflow
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.
by NoRpiuS
CVE-2004-0286 EXPLOITDB c VERIFIED
Robotftp Server - Buffer Overflow
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long username.
by gsicht
CVE-2003-0818 EXPLOITDB c VERIFIED
Microsoft ASN.1 library - RCE
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microsoft executables and libraries on Windows NT 4.0, 2000, and XP, allow remote attackers to execute arbitrary code via ASN.1 BER encodings with (1) very large length fields that cause arbitrary heap data to be overwritten, or (2) modified bit strings.
by Christophe Devine
CVE-2004-0292 EXPLOITDB c VERIFIED
Karjasoft Sami HTTP Server - Buffer Overflow
Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request.
by badpack3t
CVE-2004-2093 EXPLOITDB c VERIFIED
rsync <2.5.7 - Buffer Overflow
Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond those that are already available to the user. Therefore this issue may be REJECTED in the future.
by Abhisek Datta
CVE-2004-0282 EXPLOITDB c VERIFIED
Crob FTP Server - Denial of Service
Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disconnecting from the server.
by gsicht
CVE-2004-2074 EXPLOITDB c VERIFIED
Dream FTP 1.02 - DoS
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.
by Skylined
CVE-2004-0264 EXPLOITDB c VERIFIED
Jim Rees Httpd - Denial of Service
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.
by shaun2k2
CVE-2004-2077 EXPLOITDB c VERIFIED
Nadeo Game Engine - DoS
Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.
by scrap
CVE-2004-0277 EXPLOITDB c VERIFIED
Bolintech Dream FTP Server - Denial of Service
Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.
by shaun2k2
CVE-2004-2073 EXPLOITDB c VERIFIED
Linux-VServer 1.24 - Privilege Escalation
Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command.
by Markus Mueller
CVE-2004-0238 EXPLOITDB c VERIFIED
0verkill - Buffer Overflow
Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.
by pi3ki31ny
CVE-2004-2111 EXPLOITDB c VERIFIED
Serv-U FTP Server <4.2 - Buffer Overflow
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.
by Skylined
CVE-2004-2111 EXPLOITDB c VERIFIED
Serv-U FTP Server <4.2 - Buffer Overflow
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.
by lion
CVE-2004-2111 EXPLOITDB c VERIFIED
Serv-U FTP Server <4.2 - Buffer Overflow
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.
CVE-2004-2111 EXPLOITDB c VERIFIED
Serv-U FTP Server <4.2 - Buffer Overflow
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.
by mandragore
CVE-2004-2099 EXPLOITDB c VERIFIED
Need for Speed Hot Pursuit 2.0 <242 - Buffer Overflow
Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (servers) to execute arbitrary code via long (1) gamename, (2) gamever, (3) hostname, (4) gametype, (5) mapname or (6) gamemode commands.
by Luigi Auriemma
CVE-2004-0095 EXPLOITDB c VERIFIED
Mcafee Epolicy Orchestrator - Buffer Overflow
McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.
by cyber_flash
CVE-2004-0064 EXPLOITDB c VERIFIED
SuSE 9.0 - Local Privilege Escalation
The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.
by l0om
CVE-2003-0985 EXPLOITDB c VERIFIED
Linux Kernel - Denial of Service
The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does not properly perform bounds checks, which allows local users to cause a denial of service and possibly gain privileges by causing a remapping of a virtual memory area (VMA) to create a zero length VMA, a different vulnerability than CAN-2004-0077.
by Paul Starzetz
EIP-2026-103972 EXPLOITDB c VERIFIED
lionmax software www file share pro 2.4x - Multiple Vulnerabilities (2)
by Luigi Auriemma
EIP-2026-103971 EXPLOITDB c VERIFIED
lionmax software www file share pro 2.4x - Multiple Vulnerabilities (1)
by Luigi Auriemma
CVE-2003-0963 EXPLOITDB c VERIFIED
Alexander V. Lukyanov Lftp - Buffer Overflow
Buffer overflows in (1) try_netscape_proxy and (2) try_squid_eplf for lftp 2.6.9 and earlier allow remote HTTP servers to execute arbitrary code via long directory names that are processed by the ls or rels commands.
by Li0n7