Exploitdb Exploits

3,149 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-102875 EXPLOITDB c VERIFIED
Ifenslave 0.0.7 - Argument Local Buffer Overflow (2)
by jsk
EIP-2026-118734 EXPLOITDB c VERIFIED
Magic Winmail Server 2.3 USER POP3 - Command Format String
by D4rkGr3y
CVE-2003-0019 EXPLOITDB c VERIFIED
kernel-utils - Privilege Escalation
uml_net in the kernel-utils package for Red Hat Linux 8.0 has incorrect setuid root privileges, which allows local users to modify network interfaces, e.g. by modifying ARP entries or placing interfaces into promiscuous mode.
CVE-2003-0325 EXPLOITDB c VERIFIED
Maelstrom <3.0.6-3.0.5 - RCE
Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.
by ph4nt0m
CVE-2003-0339 EXPLOITDB c VERIFIED
WsMp3d <0.0.10 - RCE
Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP requests.
by Xpl017Elz
EIP-2026-102952 EXPLOITDB c VERIFIED
Polymorph 0.4 - Filename Buffer Overflow
by demz
CVE-2003-0306 EXPLOITDB c VERIFIED
EXPLORER.EXE <Windows XP - RCE
Buffer overflow in EXPLORER.EXE on Windows XP allows attackers to execute arbitrary code as the XP user via a desktop.ini file with a long .ShellClassInfo parameter.
by einstein
EIP-2026-102570 EXPLOITDB c VERIFIED
BZFlag 1.7 g0 - Reconnect Denial of Service
by russian code molester
EIP-2026-102917 EXPLOITDB c VERIFIED
Maelstrom Player 3.0.x - Argument Buffer Overflow (2)
by knight420
CVE-2003-0325 EXPLOITDB c VERIFIED
Maelstrom <3.0.6-3.0.5 - RCE
Buffer overflow in Maelstrom 3.0.6, 3.0.5, and earlier allows local users to execute arbitrary code via a long -server command line argument.
by CMN
CVE-2003-0293 EXPLOITDB c VERIFIED
PalmOS - DoS
PalmOS allows remote attackers to cause a denial of service (CPU consumption) via a flood of ICMP echo request (ping) packets.
by Shaun Colley
CVE-2003-0289 EXPLOITDB c VERIFIED
cdrecord <2.0 - Privilege Escalation
Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.
by CMN
CVE-2003-0201 EXPLOITDB c VERIFIED
Samba - Buffer Overflow
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.
by eDSee
CVE-2003-0281 EXPLOITDB c VERIFIED
Firebird <1.5 - Buffer Overflow
Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase codebase, allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_inet_server, (2) gds_lock_mgr, or (3) gds_drop.
by bob
CVE-2003-0290 EXPLOITDB c VERIFIED
eServ <2.9x - DoS
Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.
by rash
CVE-2002-2087 EXPLOITDB c VERIFIED
Borland Software Interbase - Buffer Overflow
Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment variable when calling (1) gds_drop, (2) gds_lock_mgr, or (3) gds_inet_server.
by bob
CVE-2003-0220 EXPLOITDB c VERIFIED
Kerio Personal Firewall <2.1.4 - RCE
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.
by Burebista
EIP-2026-114791 EXPLOITDB c VERIFIED
Mod_Gzip 1.3.x - Debug Mode
by xCrZx
CVE-2003-0262 EXPLOITDB c VERIFIED
leksbot 1.2.3 - Privilege Escalation
leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have.
by gunzip
EIP-2026-117171 EXPLOITDB c VERIFIED
FlashFXP 1.4 - User Password Encryption
by DVDMAN
CVE-2003-1480 EXPLOITDB c VERIFIED
Mysql - Cryptographic Issue
MySQL 3.20 through 4.1.0 uses a weak algorithm for hashed passwords, which makes it easier for attackers to decrypt the password via brute force methods.
by Secret Squirrel
CVE-2002-1643 EXPLOITDB c VERIFIED
Realnetworks Helix Universal Server - Buffer Overflow
Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments.
by Johnny Cyberpunk
CVE-2003-0220 EXPLOITDB c VERIFIED
Kerio Personal Firewall <2.1.4 - RCE
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute arbitrary code via a handshake packet.
by ThreaT
CVE-2003-0161 EXPLOITDB c VERIFIED
Hp-ux - Buffer Overflow
The prescan() function in the address parser (parseaddr.c) in Sendmail before 8.12.9 does not properly handle certain conversions from char and int types, which can cause a length check to be disabled when Sendmail misinterprets an input value as a special "NOCHAR" control value, allowing attackers to cause a denial of service and possibly execute arbitrary code via a buffer overflow attack using messages, a different vulnerability than CVE-2002-1337.
by bysin
CVE-2003-0190 EXPLOITDB c VERIFIED
Openbsd Openssh < 3.6.1 - Information Disclosure
OpenSSH-portable (OpenSSH) 3.6.1p1 and earlier with PAM support enabled immediately sends an error message when a user does not exist, which allows remote attackers to determine valid usernames via a timing attack.
by Maurizio Agazzini