C Exploits
3,628 exploits tracked across all sources.
BrightStor ARCserve Backup Agent for SQL Server 11.0 - Buffer Overflow
Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Server 11.0 allows remote attackers to execute arbitrary code via a long string sent to port (1) 6070 or (2) 6050.
by cybertronic
CA Products <11.5 SP1 - Buffer Overflow
Buffer overflow in the BrightStor Backup Discovery Service in multiple CA products, including ARCserve Backup r11.5 SP1 and earlier, ARCserve Backup 9.01 up to 11.1, Enterprise Backup 10.5, and CA Server Protection Suite r2, allows remote attackers to execute arbitrary code via unspecified vectors.
by cybertronic
CA BrightStor ARCserve Backup - 'dsconfig.exe' Remote Buffer Overflow
by cybertronic
Quick 'n Easy FTP Server 3.0 - Denial of Service via Long USER Command
Quick 'n Easy FTP Server 3.0 allows remote attackers to cause a denial of service (application crash or CPU consumption) via a long USER command.
by Kozan
Microsoft Windows - 'LegitCheckControl.dll' Genuine Advantage Validation Patch
by HaCkZaTaN
BusinessMail 4.60.00 - Denial of Service via Long SMTP HELO or MAIL FROM Command
Multiple buffer overflows in BusinessMail 4.60.00 allow remote attackers to cause a denial of service (application crash) via a long string to SMTP (1) HELO or (2) MAIL FROM commands.
by Kozan
GNU Mailutils < 0.6.90 - Remote Code Execution via IMAP Command Tag Format String
Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands.
by CoKi
Microsoft Color Management Module - RCE
Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.
by snooq
NetPanzer <= 0.8 - Denial of Service via Zero Datablock Size Packet
NetPanzer 0.8 and earlier allows remote attackers to cause a denial of service (infinite loop) via a packet with a zero datablock size.
by Luigi Auriemma
SoftiaCom wMailServer 1.0 and 2.0 - Denial of Service via Large TCP Packet with Leading Space
SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space, possibly triggering a buffer overflow.
by Kozan
PHPsFTPd 0.2/0.4 - 'Inc.login.php' Privilege Escalation
by Stefan Lochbihler
SoftiaCom wMailServer 1.0 - Local Information Disclosure
by fRoGGz
PrivaShare 1.1b - Denial of Service via Malformed Message
PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.
by basher13
Internet Download Manager 4.05 - Stack-based Buffer Overflow via Long URL
Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.
by c0d3r
Sudo 1.3.1 < 1.6.8p (OpenBSD) - Pathname Validation Privilege Escalation
by RusH
Nokia Affix 2.1.2 and 3.2.0 - Buffer Overflow via Long Filename in OBEX File Share
Buffer overflow in Bluetooth FTP client (BTFTP) in Nokia Affix 2.1.2 and 3.2.0 allows remote attackers to execute arbitrary code via a long filename in an OBEX file share.
by Kevin Finisterre
Microsoft Windows 2000 and XP SP1 - Remote Code Execution via Message Queuing Buffer Overflow
Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.
by houseofdabus
Solaris 8-10 - Privilege Escalation via LD_AUDIT Environment Variable
The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.
by Przemyslaw Frasunek
Solaris 8-10 - Privilege Escalation via LD_AUDIT Environment Variable
The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.
by Przemyslaw Frasunek
K-COLLECT CSV_DB.CGI 1.0/i_DB.CGI 1.0 - Remote Command Execution
by blahplok
By Source