Exploitdb Exploits

2,009 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-113775 EXPLOITDB html VERIFIED
WordPress Plugin Fuctweb CapCC 1.0 - 'plugins.php' SQL Injection
by MustLive
CVE-2008-4844 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 - Use-After-Free via DSO Bindings
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet Explorer 5.01, 6, 6 SP1, and 7 allows remote attackers to execute arbitrary code via DSO bindings involving (1) an XML Island, (2) XML DSOs, or (3) Tabular Data Control (TDC) in a crafted HTML or XML document, as demonstrated by nested SPAN or MARQUEE elements, and exploited in the wild in December 2008.
by muts
CVE-2008-6447 EXPLOITDB html VERIFIED
QuikSoft EasyMail MailStore ActiveX emmailstore.dll 6.5.0.3 - Buffer Overflow via CreateStore Method
Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to execute arbitrary code via a long first argument to the CreateStore method.
by e.wiZz!
CVE-2008-6975 EXPLOITDB html VERIFIED
DD-WRT 24 sp2 - Cross-Site Request Forgery via apply.cgi Parameters
Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the ping_ip parameter; (2) change the administrative credentials via the http_username and http_passwd parameters; (3) enable remote administration via the remote_management parameter; or (4) configure port forwarding via certain from, to, ip, and pro parameters. NOTE: This issue reportedly exists because of a "weak ... anti-CSRF fix" implemented in 24 sp2.
by Michael Brooks
CVE-2008-6496 EXPLOITDB html VERIFIED
VISAGESOFT eXPert PDF EditorX 1.0.200.0 - Arbitrary File Write via extractPagesToFile
Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows remote attackers to create or overwrite arbitrary files via the first argument to the extractPagesToFile method.
by Marco Torti
EIP-2026-115347 EXPLOITDB html VERIFIED
Google Chrome - MetaCharacter URI Obfuscation
by Aditya K Sood
CVE-2008-4033 EXPLOITDB html VERIFIED
Microsoft XML Core Services 3.0-6.0 - Info Disclosure
Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attackers to obtain sensitive information from another domain and corrupt the session state via HTTP request header fields, as demonstrated by the Transfer-Encoding field, aka "MSXML Header Request Vulnerability."
by Jerome Athias
CVE-2008-7070 EXPLOITDB html VERIFIED
KVIrc 3.4.2 - Remote Code Execution via URI Handler Argument Injection
Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary commands via a " (quote) followed by command line switches in a (1) irc:///, (2) irc6:///, (3) ircs:///, or (4) and ircs6:/// URI. NOTE: this might be due to an incomplete fix for CVE-2007-2951.
by Nine:Situations:Group
CVE-2008-6936 EXPLOITDB html VERIFIED
Exodus 0.10 - Argument Injection via Encoded Spaces in pres:// URI
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in a pres:// URI, a different vector than CVE-2008-6935.
by Nine:Situations:Group
CVE-2008-6935 EXPLOITDB html VERIFIED
Exodus 0.10 - Argument Injection via Encoded Spaces in im:// URI
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an im:// URI.
by Nine:Situations:Group
CVE-2008-6937 EXPLOITDB html VERIFIED
Exodus 0.10 - Argument Injection via Encoded Spaces in xmpp:// URI
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, overwrite arbitrary files, and cause a denial of service via encoded spaces in an xmpp:// URI, a different vector than CVE-2008-6935 and CVE-2008-6936. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Nine:Situations:Group
EIP-2026-109008 EXPLOITDB html VERIFIED
Kimson CMS - 'id' Cross-Site Scripting
by md.r00t
CVE-2008-5183 EXPLOITDB HIGH html VERIFIED
CUPS < 1.3.9 - Denial of Service via RSS Subscription NULL Pointer Dereference
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.
by Adrian _pagvac_ Pastor
CVSS 7.5
CVE-2008-5178 EXPLOITDB html VERIFIED
Opera 9.62 - Remote Code Execution via Long file:// URI
Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file:// URI. NOTE: this might overlap CVE-2008-5680.
by Guido Landi
CVE-2008-6959 EXPLOITDB html VERIFIED
Chilkat Socket ActiveX <2.3.1.1 - RCE
Insecure method vulnerability in the Chilkat Socket ActiveX control (ChilkatSocket.ChilkatSocket.1) in ChilkatSocket.dll 2.3.1.1 allows remote attackers to overwrite arbitrary files via the SaveLastError method. NOTE: this might be related to CVE-2008-1647.
by Zigma
CVE-2008-5680 EXPLOITDB html VERIFIED
Opera < 9.63 - Remote Code Execution via Crafted Text Area
Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted text area, or allow (2) user-assisted remote attackers to execute arbitrary code via a long host name in a file: URL. NOTE: this might overlap CVE-2008-5178.
by Guido Landi
CVE-2008-5492 EXPLOITDB html VERIFIED
VeryDOC PDF Viewer OCX Control <2.0.0.1 - Buffer Overflow
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX Control allows remote attackers to execute arbitrary code via a long first argument to the OpenPDF method. NOTE: some of these details are obtained from third party information.
by r0ut3r
CVE-2008-5115 EXPLOITDB html VERIFIED
Sun Java System Identity Manager 6.0-6.0 SP4, 7.0, 7.1 - Cross-Site Request Forgery via Password Update
Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp.
by Richard Brain
CVE-2008-5002 EXPLOITDB html VERIFIED
Chilkat Crypt ActiveX Control - Arbitrary File Write via WriteFile Method
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilkat Crypt ActiveX Component allows remote attackers to create and overwrite arbitrary files via the WriteFile method. NOTE: this could be leveraged for code execution by creating executable files in Startup folders or by accessing files using hcp:// URLs. NOTE: some of these details are obtained from third party information.
by shinnai
CVE-2011-5289 EXPLOITDB html VERIFIED
aTube Catcher 2.3.570 - Arbitrary File Write via SaveDecrypted Method
The SaveDecrypted method in the ChilkatCrypt2.ChilkatOmaDrm.1 ActiveX control in ChilkatCrypt2.dll in aTube Catcher 2.3.570 allows remote attackers to write to arbitrary files via a pathname in the argument.
by shinnai
EIP-2026-119003 EXPLOITDB html VERIFIED
Opera Web Browser 9.62 - History Search Input Validation
by NeoCoderz
EIP-2026-118999 EXPLOITDB html VERIFIED
Opera 9.61 - 'opera:historysearch' Code Execution
by Aviv Raff
CVE-2008-4922 EXPLOITDB html VERIFIED
DjVu ActiveX Control for Microsoft Office - Buffer Overflow via ImageURL Property
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers to execute arbitrary code via a long (1) ImageURL property, and possibly the (2) Mode, (3) Page, or (4) Zoom properties.
by Shahriyar Jalayeri
CVE-2008-4800 EXPLOITDB html VERIFIED
Microsoft Debug Diagnostic Tool - Denial of Service via GetEntryPointForThread Method
The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attackers to cause a denial of service (NULL pointer dereference and Internet Explorer 6.0 crash) via a large negative integer argument to the GetEntryPointForThread method. NOTE: this issue might only be exploitable in limited environments or non-default browser settings.
by suN8Hclf
CVE-2008-4795 EXPLOITDB html VERIFIED
Opera < 9.62 - Cross-Site Scripting via Links Panel
The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which allows remote attackers to inject arbitrary web script or HTML via cross-site scripting (XSS) attacks.
by Stefano Di Paola