Exploitdb Exploits

2,009 exploits tracked across all sources.

Sort: Activity Stars
CVE-2008-6997 EXPLOITDB html VERIFIED
Google Chrome 0.2.149.27 - Denial of Service via Long IMG src Attribute
Google Chrome 0.2.149.27 allows user-assisted remote attackers to cause a denial of service (browser crash) via an IMG tag with a long src attribute, which triggers the crash when the victim performs an "Inspect Element" action.
by Metacortex
CVE-2008-6998 EXPLOITDB html VERIFIED
Google Chrome < 0.2.149.29 - Stack-Based Buffer Overflow via Hover Over Long Path Link
Stack-based buffer overflow in chrome/common/gfx/url_elider.cc in Google Chrome 0.2.149.27 and other versions before 0.2.149.29 might allow user-assisted remote attackers to execute arbitrary code via a link target (href attribute) with a large number of path elements, which triggers the overflow when the status bar is updated after the user hovers over the link.
by Shinnok
CVE-2008-7061 EXPLOITDB html VERIFIED
Google Chrome 0.2.149.29 - Denial of Service via Long Title Attribute in Tooltip
The tooltip manager (chrome/views/tooltip_manager.cc) in Google Chrome 0.2.149.29 Build 1798 and possibly other versions before 0.2.149.30 allows remote attackers to cause a denial of service (CPU consumption or crash) via a tag with a long title attribute, which is not properly handled when displaying a tooltip, a different vulnerability than CVE-2008-6994. NOTE: there is inconsistent information about the environments under which this issue exists.
by Exodus
CVE-2008-3892 EXPLOITDB html VERIFIED
VMware <5.5.8-6.0.5-1.0.8-2.0.5-1.0.7 - Buffer Overflow
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMware ACE 1.x before 1.0.7 build 108880, VMware ACE 2.x before 2.0.5 build 109488, and VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (browser crash) or possibly execute arbitrary code via a call to the GuestInfo method in which there is a long string argument, and an assignment of a long string value to the result of this call. NOTE: this may overlap CVE-2008-3691, CVE-2008-3692, CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, or CVE-2008-3696.
by shinnai
CVE-2008-4050 EXPLOITDB html VERIFIED
Friendly Technologies FriendlyPPPoE Client <3.0.0.57 - Code Injection
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to (1) create and read arbitrary registry values via the RegistryValue method, and (2) read arbitrary files via the GetTextFile method.
by spdr
CVE-2008-7103 EXPLOITDB html VERIFIED
Najdi.si Toolbar 2.0.4.1 - Stack-Based Buffer Overflow via Document.Location Property
Stack-based buffer overflow in an ActiveX control in najdisitoolbar.dll in Najdi.si Toolbar 2.0.4.1 allows remote attackers to cause a denial of service (browser crash) or execute arbitrary code via a long Document.Location property value.
by shinnai
CVE-2008-7053 EXPLOITDB html VERIFIED
LogMeIn RACtrl.dll - Denial of Service via fgcolor and bgcolor Property Manipulation
LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash) by setting the fgcolor and bgcolor properties to certain long values that trigger memory corruption.
by YAG KOHHA
CVE-2008-4048 EXPLOITDB html VERIFIED
Friendly Technologies FriendlyPPPoE Client <3.0.0.57 - Buffer Overflow
Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary code via a long third argument to the CreateURLShortcut method.
by spdr
CVE-2008-4049 EXPLOITDB html VERIFIED
Friendly Technologies FriendlyPPPoE Client <3.0.0.57 - RCE
A certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPoE Client 3.0.0.57 allows remote attackers to execute arbitrary programs via arguments to the RunApp method.
by spdr
CVE-2008-3878 EXPLOITDB html VERIFIED
Ultra Office Control <2.0.2008.801 - Buffer Overflow
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware Ultra Office Control allows remote attackers to execute arbitrary code via long strUrl, strFile, and strPostData parameters to the HttpUpload method.
by shinnai
CVE-2008-3879 EXPLOITDB html VERIFIED
Ultra Office Control 2.0.2008.801 - RCE
The Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 and earlier in Ultra Shareware Ultra Office Control allows remote attackers to force the download of arbitrary files onto a client system via a URL in the first argument to the Open method, in conjunction with a full destination pathname in the first argument (SaveAsDocument argument) to the Save method.
by shinnai
CVE-2008-3704 EXPLOITDB html VERIFIED
Microsoft Visual Studio <6.0.84.18 - Buffer Overflow
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions before 6.0.84.18, in Microsoft Visual Studio 6.0, Visual Basic 6.0, Visual Studio .NET 2002 SP1 and 2003 SP1, and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 allows remote attackers to execute arbitrary code via a long Mask parameter, related to not "validating property values with boundary checks," as exploited in the wild in August 2008, aka "Masked Edit Control Memory Corruption Vulnerability."
by Koshi
CVE-2008-7115 EXPLOITDB html VERIFIED
Belkin Wireless G Router F5D7632-4V6 - Unauthenticated Privilege Escalation via Direct CGI Request
The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication and gain administrator privileges via a direct request to (1) statusprocess.exe, (2) system_all.exe, or (3) restore.exe in cgi-bin/. NOTE: the setup_dns.exe vector is already covered by CVE-2008-1244.
by noensr
CVE-2008-5232 EXPLOITDB html VERIFIED
Microsoft Windows Media Services <4.1.00.3917 - RCE
Buffer overflow in the CallHTMLHelp method in the Microsoft Windows Media Services ActiveX control in nskey.dll 4.1.00.3917 in Windows Media Services on Microsoft Windows NT and 2000, and Avaya Media and Message Application servers, allows remote attackers to execute arbitrary code via a long argument. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Jeremy Brown
CVE-2008-3558 EXPLOITDB html VERIFIED
Cisco WebEx Meeting Manager <20.2008.2606.4919 - Buffer Overflow
Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before 20.2008.2606.4919 allows remote attackers to execute arbitrary code via a long argument to the NewObject method.
by Guido Landi
CVE-2008-3702 EXPLOITDB html VERIFIED
JComSoft AniGIF.ocx <2.47 - Buffer Overflow
Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used in products such as SpeedBit Download Accelerator Plus (DAP) 8.6, allow remote attackers to execute arbitrary code via a long argument to the (1) ReadGIF or (2) ReadGIF2 method.
by Guido Landi
CVE-2008-3578 EXPLOITDB html VERIFIED
hydrairc < 0.3.164 - Denial of Service via Long irc:// URI
HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a long irc:// URI.
by securfrog
EIP-2026-118947 EXPLOITDB html VERIFIED
NCTsoft - 'AudFile.dll' ActiveX Control Remote Buffer Overflow
by shinnai
CVE-2008-2321 EXPLOITDB html VERIFIED
CoreGraphics - Remote Code Execution or Denial of Service via Argument Processing
Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unknown vectors involving "processing of arguments."
by Michal Zalewski
CVE-2008-3364 EXPLOITDB html VERIFIED
Trend Micro OfficeScan <7.3.0.1020 - RCE
Buffer overflow in the ObjRemoveCtrl Class ActiveX control in OfficeScanRemoveCtrl.dll 7.3.0.1020 in Trend Micro OfficeScan Corp Edition (OSCE) Web-Deployment 7.0, 7.3 build 1343 Patch 4 and other builds, and 8.0; Client Server Messaging Security (CSM) 3.5 and 3.6; and Worry-Free Business Security (WFBS) 5.0 allows remote attackers to execute arbitrary code via a long string in the Server property, and possibly other properties. NOTE: some of these details are obtained from third party information.
by Elazar
CVE-2008-3362 EXPLOITDB html VERIFIED
Giulio Ganci Wp Downloads Manager <0.2 - RCE
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension via the upfile parameter, then accessing it via a direct request to the file in wp-content/plugins/downloads-manager/upload/.
by SaO
CVE-2008-3242 EXPLOITDB html VERIFIED
PPMate PPMedia Class ActiveX Control - Heap-Based Buffer Overflow via StartUrl Method
Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attackers to execute arbitrary code via a long argument to the StartUrl method. NOTE: some of these details are obtained from third party information.
by Guido Landi
CVE-2008-3209 EXPLOITDB html VERIFIED
Black Ice Document Imaging SDK 10.95 - Buffer Overflow
Heap-based buffer overflow in the OpenGifFile function in BiGif.dll in Black Ice Document Imaging SDK 10.95 allows remote attackers to execute arbitrary code via a long string argument to the GetNumberOfImagesInGifFile method in the BIImgFrm Control ActiveX control in biimgfrm.ocx. NOTE: some of these details are obtained from third party information.
by r0ut3r
CVE-2008-6442 EXPLOITDB html VERIFIED
Sina Inc. DLoader Class ActiveX - File Overwrite
Insecure method vulnerability in Sina Inc. DLoader Class ActiveX Control allows remote attackers to overwrite arbitrary files via a URL in the first parameter to the DonwloadAndInstall method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by Symantec
EIP-2026-116631 EXPLOITDB html VERIFIED
Yahoo Messenger 8.1 - ActiveX Remote Denial of Service
by Jeremy Brown