Exploitdb Exploits
3,138 exploits tracked across all sources.
Progress Database 9.1-9.1D06 - Privilege Escalation
Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to gain privileges via (1) a PATH environment variable that points to malicious libraries, as demonstrated using libjutil.so in_proapsv, or (2) the -installdir command line parameter, as demonstrated using librocket_r.so in _dbagent.
by kf
Magic WinMail Server <2.x - DoS/RCE
Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command.
by ThreaT
ArGoSoft Mail Server 1.8.3.5 - GET Multiple Denial of Service Vulnerabilities
by posidron
atftpd 0.6.1 - Buffer Overflow via Long Filename
Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename.
by gunzip
Xaos <3.0-23 - Privilege Escalation
Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.
KON kon2 <0.3.9b - Remote Code Execution
Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.
by c0ntex
pi3web 2.0.2 Beta 1 - Denial of Service via Malformed URL
Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the column title as a hyperlink, allows remote attackers to cause a denial of service (crash) via a malformed URL to the web server, possibly involving a buffer overflow.
by posidron
Windows 2000 - Remote Code Execution via WebDAV Request
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows remote attackers to execute arbitrary code, as demonstrated via a WebDAV request to IIS 5.0.
by alumni
Microsoft Internet Information Services 5.0-5.1 - Denial of Service via Long WebDAV PROPFIND or SEARCH Request
Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.
by Shachank
Desktop Orbiter 2.0 1 - Resource Exhaustion (Denial of Service)
by Luca Ercoli
Activity Monitor 2002 2.6 - Remote Denial of Service
by Luca Ercoli
Microsoft Internet Information Services 5.0-5.1 - Denial of Service via Long WebDAV PROPFIND or SEARCH Request
Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a long WebDAV request with a (1) PROPFIND or (2) SEARCH method, which generates an error condition that is not properly handled.
by Neo1
Uptime Client <5.0b7 - Privilege Escalation
Buffer overflow in Uptime Client (UpClient) 5.0b7, and possibly other versions, allows local users to gain privileges via a long -p argument.
by Gino Thomas
Gnome Batalla Naval 1.0.4 - Remote Code Execution via Long Connection String
Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.
by jsk
Ifenslave 0.0.7 - Argument Local Buffer Overflow (3)
by Julien L
Magic Winmail Server 2.3 USER POP3 - Command Format String
by D4rkGr3y
kernel-utils - Privilege Escalation
uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.
Maelstrom <= 3.0.6 - Buffer Overflow via Long Server Command Line Argument
Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.
by ph4nt0m
WsMp3 daemon 0.0.10 - Remote Code Execution via Long HTTP Requests
Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP requests.
by Xpl017Elz
Windows XP - Buffer Overflow via Long .ShellClassInfo Parameter in desktop.ini
Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.
by einstein
By Source