Exploitdb Exploits
3,138 exploits tracked across all sources.
GKrellM Mailwatch Plugin 2.4.1/2.4.2 - From Header Remote Buffer Overflow
by isox
Essentia Web Server 2.15 - Remote Code Execution via Long URI
Stack-based buffer overflow in Essentia Web Server 2.15 for Windows allows remote attackers to execute arbitrary code via a long URI, as demonstrated by a GET or HEAD request. NOTE: some of these details are obtained from third party information.
by B-r00t
ISDNRep 4.56 - Command Line Argument Local Buffer Overflow (2)
by snooq
ISDNRep 4.56 - Command Line Argument Local Buffer Overflow (1)
by ace
eXtremail <= 1.1.9 - Format String Vulnerability via SMTP and POP3 Commands
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6) other commands that can be executed after POP3 authentication.
by B-r00t
Microsoft Windows Media Services <5.0 - RCE
Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.
by firew0rker
ezbounce 1.0-1.50 - Remote Code Execution via Sessions Command Format String
Format string vulnerability in ezbounce 1.0 through 1.50 allows remote attackers to execute arbitrary code via the "sessions" command.
by V9
Kerio MailServer 5.6.3 - Buffer Overflow
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parameter in the do_subscribe module, (2) a long folder parameter in the add_acl module, (3) a long folder parameter in the list module, and (4) a long user parameter in the do_map module.
by B-r00t
AndromedeIRCd 1.2.3-Release - Format String Vulnerability in Debug Mode
Format string vulnerability in (1) Bahamut IRCd 1.4.35 and earlier, and other IRC daemons based on Bahamut including (2) digatech 1.2.1, (3) methane 0.1.1, (4) AndromedeIRCd 1.2.3-Release, and (5) ircd-RU, when running in debug mode, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request containing format strings.
by Dinos
Mandrake Multi Network Firewall - Denial of Service via execve Race Condition
A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).
by IhaQueR
Microsoft Windows Media Services <5.0 - RCE
Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability of Microsoft Windows Media Services (nsiislog.dll), as installed in IIS 5.0, allows remote attackers to execute arbitrary code via a large POST request to nsiislog.dll.
by firew0rker
Alt-N WebAdmin - Buffer Overflow via USER Argument
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument.
by Mark Litchfield
Alt-N WebAdmin - Buffer Overflow via USER Argument
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument.
by Mark Litchfield
Tripbit Secure Code Analizer 1.0 - 'fgets()' Local Buffer Overrun
by posidron
Yahoo! Messenger 5.0.0.1064 - Remote Code Execution via Long YMSGR URI Arguments
Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsgr URI with long arguments to (1) call, (2) sendim, (3) getimv, (4) chat, (5) addview, or (6) addfriend.
by Rave
Armida Databased Web Server 1.0 - GET Remote Denial of Service
by posidron
GNU GNATS 3.113 - Environment Variable Buffer Overflow
by Xpl017Elz
Linux Kernel - Information Disclosure via /proc Filesystem
The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/self before executing a setuid program, which causes the program to fail to change the ownership and permissions of those entries.
by IhaQueR
Abuse-SDL 0.7 - Command Line Argument Buffer Overflow
by Matrix_DK
By Source