Exploitdb Exploits

2,012 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-119151 EXPLOITDB html VERIFIED
SmartVmd ActiveX 1.1 - Remote File Deletion
by Houssamix
EIP-2026-118777 EXPLOITDB html VERIFIED
MetaProducts MetaTreeX 1.5.100 - ActiveX File Overwrite
by Houssamix
EIP-2026-118357 EXPLOITDB html VERIFIED
Ciansoft PDFBuilderX 2.2 - ActiveX Arbitrary File Overwrite
by Alfons Luja
EIP-2026-118524 EXPLOITDB html VERIFIED
Excel Viewer OCX 3.2 - Remote Command Execution
by Stack
EIP-2026-118501 EXPLOITDB html VERIFIED
EDraw Office Viewer 5.4 - 'HttpDownloadFile()' Insecure Method
by Cyber-Zone
CVE-2009-0134 EXPLOITDB html VERIFIED
EasyGrid ActiveX <3.51 - DoS
Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX 3.51 allows remote attackers to create and overwrite arbitrary files via the (1) DoSaveFile or (2) DoSaveHtmlFile method. NOTE: vector 1 could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.
by Houssamix
EIP-2026-119293 EXPLOITDB html VERIFIED
Word Viewer OCX 3.2 - Remote Command Execution
by Stack
EIP-2026-119292 EXPLOITDB html VERIFIED
Word Viewer OCX 3.2 - ActiveX 'Save' Remote File Overwrite
by Houssamix
EIP-2026-119049 EXPLOITDB html VERIFIED
PowerPoint Viewer OCX 3.1 - Remote Command Execution
by Cyber-Zone
EIP-2026-118981 EXPLOITDB html VERIFIED
Office Viewer ActiveX Control 3.0.1 - Remote Command Execution
by Houssamix
EIP-2026-118980 EXPLOITDB html VERIFIED
Office Viewer ActiveX Control 3.0.1 - 'Save' Remote File Overwrite
by Houssamix
EIP-2026-116091 EXPLOITDB html VERIFIED
PowerPoint Viewer OCX 3.1 - Remote File Overwrite
by Stack
EIP-2026-118525 EXPLOITDB html VERIFIED
ExcelOCX ActiveX 3.2 - Download File Insecure Method
by Alfons Luja
EIP-2026-100224 EXPLOITDB html VERIFIED
Comersus Shopping Cart 6.0 - Remote User Pass
by ajann
EIP-2026-100221 EXPLOITDB html VERIFIED
Comersus Cart 6 - User Email and User Password Unauthorized Access
by ajann
EIP-2026-115667 EXPLOITDB html VERIFIED
Microsoft Internet Explorer - JavaScript screen[ ] Denial of Service
by Skylined
CVE-2009-0070 EXPLOITDB html VERIFIED
Apple Safari - Memory Corruption
Integer signedness error in Apple Safari allows remote attackers to read the contents of arbitrary memory locations, cause a denial of service (application crash), and probably have unspecified other impact via the array index of the arguments array in a JavaScript function, possibly a related issue to CVE-2008-2307.
by Skylined
CVE-2008-6748 EXPLOITDB html VERIFIED
Megacubo - Code Injection
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI.
by JJunior
CVE-2008-6748 EXPLOITDB html VERIFIED
Megacubo - Code Injection
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the play action in a mega:// URI.
by Nine:Situations:Group
CVE-2008-6898 EXPLOITDB html VERIFIED
Saschart Sascam Webcam Server - Memory Corruption
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the Get method and other unspecified methods.
by callAX
CVE-2008-4584 EXPLOITDB html VERIFIED
Chilkat Mail <7.8 - File Overwrite
Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite arbitrary files via a full pathname to the SaveLastError method.
by callAX
CVE-2008-5749 EXPLOITDB html VERIFIED
Google Chrome <1.0.154.36 - Command Injection
Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI. NOTE: a third party disputes this issue, stating that Chrome "will ask for user permission" and "cannot launch the applet even [if] you have given out the permission.
by Nine:Situations:Group
CVE-2008-5750 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 8 beta 2 - Command Injection
Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to execute arbitrary commands via the --renderer-path option in a chromehtml: URI.
by Nine:Situations:Group
CVE-2008-5691 EXPLOITDB html VERIFIED
Phoenician Casino FlashAX <1.0.0.7 - Buffer Overflow
Heap-based buffer overflow in the Phoenician Casino FlashAX ActiveX control 1.0.0.7 allows remote attackers to execute arbitrary code via a long argument to the SetID method.
by e.wiZz!
CVE-2008-4844 EXPLOITDB html VERIFIED
Microsoft Internet Explorer - Resource Management Error
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
by krafty