Html Exploits

2,054 exploits tracked across all sources.

Sort: Activity Stars
CVE-2011-1519 EXPLOITDB html VERIFIED
IBM Lotus Domino <8.x - Auth Bypass
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.
by Alexey Sintsov
EIP-2026-103575 EXPLOITDB html VERIFIED
Mozilla Firefox 8.0 - Null Pointer Dereference (PoC)
by 0in
CVE-2011-4709 EXPLOITDB html VERIFIED
Hotaru Search Plugin - XSS
Multiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in the Search plugin 1.3 for Hotaru CMS allow remote attackers to inject arbitrary web script or HTML via the (1) SITE_NAME parameter to admin_index.php, or the (2) return and (3) search parameters to index.php. NOTE: some of these details are obtained from third party information.
by Gjoko Krstic
CVE-2011-5167 EXPLOITDB html VERIFIED
Oracle Hyperion Strategic Finance < 12.0 - Memory Corruption
Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Build 1 in Oracle Hyperion Strategic Finance 12.x and possibly earlier allows remote attackers to execute arbitrary code via a long string to the DriverName parameter.
by rgod
EIP-2026-119005 EXPLOITDB html VERIFIED
Oracle AutoVue 20.0.1 - 'AutoVueX.ocx' ActiveX Control 'ExportEdaBom()' Insecure Method
by rgod
EIP-2026-116001 EXPLOITDB html
Opera 11.51 - Use-After-Free Crash (PoC)
by Roberto Suggi Liverani
EIP-2026-116003 EXPLOITDB html VERIFIED
Opera 11.52 - Stack Overflow
by pigtail23
EIP-2026-116002 EXPLOITDB html VERIFIED
Opera 11.52 - Denial of Service (PoC)
by pigtail23
CVE-2011-2371 EXPLOITDB html VERIFIED
Mozilla Seamonkey < 3.6.17 - Numeric Error
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via vectors involving a long JavaScript Array object.
by ryujin
CVE-2011-1999 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 8 - RCE
Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arbitrary code via vectors involving a "dereferenced memory address," aka "Select Element Remote Code Execution Vulnerability."
by Ivan Fratric
EIP-2026-115154 EXPLOITDB html VERIFIED
DivX Plus Web Player - 'file://' Buffer Overflow (PoC)
by Snake
EIP-2026-109271 EXPLOITDB html VERIFIED
Mambo 4.6.5 - 'index.php' Cross-Site Request Forgery
by Caddy-Dz
EIP-2026-117152 EXPLOITDB html VERIFIED
F-Secure (Multiple Products) - ActiveX HeapSpray Overwrite (SEH)
by 41.w4r10r
EIP-2026-119171 EXPLOITDB html VERIFIED
StudioLine Photo Basic 3.70.34.0 - 'NMSDVDXU.dll' ActiveX Control Arbitrary File Overwrite
by High-Tech Bridge SA
CVE-2011-0065 EXPLOITDB html VERIFIED
Mozilla Firefox <3.5.19 & SeaMonkey <2.0.14 - Use After Free
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers to execute arbitrary code via vectors related to OBJECT's mChannel.
by mr_me
EIP-2026-118403 EXPLOITDB html VERIFIED
Dell IT Assistant - detectIESettingsForITA.ocx ActiveX Control
by rgod
EIP-2026-110453 EXPLOITDB html VERIFIED
Pandora Fms 3.2.1 - Cross-Site Request Forgery
by mehdi boukazoula
EIP-2026-119052 EXPLOITDB html VERIFIED
Pro Softnet IDrive Online Backup 3.4.0 - ActiveX 'SaveToFile()' Arbitrary File Overwrite
by High-Tech Bridge SA
EIP-2026-118678 EXPLOITDB html VERIFIED
iMesh 10.0 - 'IMWebControl.dll' ActiveX Control Buffer Overflow
by KedAns-Dz
EIP-2026-118395 EXPLOITDB html VERIFIED
CygniCon CyViewer - ActiveX Control 'SaveData()' Insecure Method
by High-Tech Bridge SA
EIP-2026-118722 EXPLOITDB html VERIFIED
LeadTools Imaging LEADSmtp - ActiveX Control 'SaveMessage()' Insecure Method
by High-Tech Bridge SA
EIP-2026-115181 EXPLOITDB html VERIFIED
Easewe FTP OCX ActiveX Control 4.5.0.9 - 'EaseWeFtp.ocx' Multiple Insecure Method Vulnerabilities
by High-Tech Bridge SA
EIP-2026-118323 EXPLOITDB html VERIFIED
Black Ice Fax Voice SDK 12.6 - Remote Code Execution
by mr_me
CVE-2011-2641 EXPLOITDB html VERIFIED
Opera Browser - Resource Management Error
Opera 11.11 allows remote attackers to cause a denial of service (application crash) by setting the FACE attribute of a FONT element within an IFRAME element after changing the SRC attribute of this IFRAME element to an about:blank value.
by echo
EIP-2026-103610 EXPLOITDB html VERIFIED
Opera Web Browser 11.11 - Denial of Service
by echo