C Exploits

3,628 exploits tracked across all sources.

Sort: Activity Stars
CVE-2005-1344 EXPLOITDB c VERIFIED
Apache HTTP Server 2.0.52 - Buffer Overflow via Long Realm Argument
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
by K-sPecial
CVE-2005-1654 EXPLOITDB c VERIFIED
Hosting Controller < 6.1 Hotfix 1.9 - Unauthenticated Arbitrary User Registration via Direct Request
Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.
by Silentium
CVE-2005-1470 EXPLOITDB c VERIFIED
Ethereal - Denial of Service in TZSP MGCP ISUP SMB or Bittorrent Dissectors
Multiple unknown vulnerabilities in the (1) TZSP, (2) MGCP, (3) ISUP, (4) SMB, or (5) Bittorrent dissectors in Ethereal before 0.10.11 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.
by Nicob
CVE-2005-1344 EXPLOITDB c VERIFIED
Apache HTTP Server 2.0.52 - Buffer Overflow via Long Realm Argument
Buffer overflow in htdigest in Apache 2.0.52 may allow attackers to execute arbitrary code via a long realm argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to an escalation of privileges, unless htdigest is executed from a CGI program. Therefore this may not be a vulnerability.
by Luca Ercoli
EIP-2026-114618 EXPLOITDB c VERIFIED
ZeroBoard - Worm Source Code
by anonymous
CVE-2005-1507 EXPLOITDB c VERIFIED
4D WebSTAR 5.33 and 5.4 - Buffer Overflow via Long URL
Buffer overflow in the Tomcat plugin in 4d WebSTAR 5.33 and 5.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL.
by Braden Thomas
EIP-2026-103101 EXPLOITDB c VERIFIED
dSMTP Mail Server 3.1b (Linux) - Format String
by cybertronic
EIP-2026-103228 EXPLOITDB c VERIFIED
Subversion 0.3.7/1.0.0 - Remote Buffer Overflow
by greuff
EIP-2026-102153 EXPLOITDB c VERIFIED
HP-UX FTPD 1.1.214.4 - 'REST' Remote Brute Force
by phased
CVE-2005-1396 EXPLOITDB c VERIFIED
Ce/Ceterm <2.5.4 - Local Privilege Escalation
Race condition in Ce/Ceterm (aka ARPUS/Ce) 2.5.4 and earlier allows local users to write to arbitrary files via a symlink attack on the ce_edit_log temporary file.
by Kevin Finisterre
CVE-2005-1394 EXPLOITDB c VERIFIED
ArcGIS for ESRI ArcInfo Workstation 9.0 - Privilege Escalation
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.
by Kevin Finisterre
CVE-2005-0634 EXPLOITDB c VERIFIED
Golden FTP Server 1.92 - Remote Code Execution via Long USER Command
Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command.
by darkeagle
CVE-2005-0634 EXPLOITDB c VERIFIED
Golden FTP Server 1.92 - Remote Code Execution via Long USER Command
Buffer overflow in Golden FTP Server 1.92 allows remote attackers to execute arbitrary code via a long USER command.
by c0d3r
CVE-2005-1246 EXPLOITDB c VERIFIED
snmppd 0.4.5 - Remote Code Execution via Format String in snmppd_log
Format string vulnerability in the snmppd_log function in snmppd_util.c for snmppd 0.4.5 and earlier may allow remote attackers to cause a denial of service or execute arbitrary code via format string specifiers that are not properly handled in a syslog call.
by cybertronic
CVE-2005-1418 EXPLOITDB c VERIFIED
NetLeaf Limited NotJustBrowsing <1.0.3 - Info Disclosure
NetLeaf Limited NotJustBrowsing 1.0.3 stores the View Lock Password in plaintext in the notjustbrowsing.prf file, which allows local users to gain privileges.
by Kozan
CVE-2005-1411 EXPLOITDB c VERIFIED
Cybration ICUII 7.0 - Info Disclosure
Cybration ICUII 7.0 stores passwords in plaintext in the world-readable icuii.ini file, which allows local users to gain privileges.
by Kozan
CVE-2005-1424 EXPLOITDB c VERIFIED
StumbleInside GoText 1.01 - Info Disclosure
StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoText.bin file, which allows local users to obtain that information.
by Kozan
CVE-2005-1414 EXPLOITDB c VERIFIED
ExoticSoft FilePocket 1.2 - Privilege Escalation
ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, which allows local users to gain privileges.
by Kozan
EIP-2026-118940 EXPLOITDB c VERIFIED
MySQL MaxDB Webtool 7.5.00.23 - Remote Stack Overflow
by cybertronic
CVE-2005-1372 EXPLOITDB c VERIFIED
BakBone NetVault 7.1 - Privilege Escalation
nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows local users to gain privileges via the Help menu.
by Reed Arvin
EIP-2026-116777 EXPLOITDB c VERIFIED
Altiris Client 6.0.88 - Service Privilege Escalation
by Reed Arvin
CVE-2005-1280 EXPLOITDB c VERIFIED
tcpdump < 3.9.1 - Denial of Service via RSVP Packet Length 4
The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted RSVP packet of length 4.
by vade79
CVE-2005-1278 EXPLOITDB c VERIFIED
tcpdump < 3.9.1 - Denial of Service via Zero-Length GRE Packet
The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop) via a zero length, as demonstrated using a GRE packet.
by vade79
CVE-2005-1279 EXPLOITDB c VERIFIED
tcpdump < 3.8.3 - Denial of Service via BGP or LDP Packet Handling
tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.
by vade79
CVE-2005-1279 EXPLOITDB c VERIFIED
tcpdump < 3.8.3 - Denial of Service via BGP or LDP Packet Handling
tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP packet, which is not properly handled by RT_ROUTING_INFO, or (2) LDP packet, which is not properly handled by the ldp_print function.
by vade79