Exploitdb Exploits

2,012 exploits tracked across all sources.

Sort: Activity Stars
CVE-2008-6565 EXPLOITDB html VERIFIED
Invision Power Services Invision Power Board < 2.3.1 - XSS
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via an IFRAME tag in the signature.
by SHAHEE_MIRZA
CVE-2008-1605 EXPLOITDB html VERIFIED
LEADTOOLS Multimedia Toolkit <15 - File Overwrite
The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0.17 and earlier) in LEADTOOLS Multimedia Toolkit 15 allow attackers to overwrite arbitrary files via the SaveSettingsToFile method.
by shinnai
EIP-2026-104614 EXPLOITDB html VERIFIED
Apple Safari 3.1 - Window.setTimeout Variant Content Spoofing
by Juan Pablo Lopez Yacubian
EIP-2026-103411 EXPLOITDB html VERIFIED
Apple Safari (webkit) (iPhone/OSX/Windows) - Remote Denial of Service
by Georgi Guninski
CVE-2008-1472 EXPLOITDB html VERIFIED
ListCtrl ActiveX Control - Buffer Overflow
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including BrightStor ARCserve Backup R11.5, Desktop Management Suite r11.1 through r11.2, and Unicenter products r11.1 through r11.2, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a long argument to the AddColumn method.
by h07
CVE-2008-1316 EXPLOITDB html VERIFIED
QT-cute QuickTalk Forum <1.6 - SQL Injection
SQL injection vulnerability in qtf_ind_search_ov.php in QT-cute QuickTalk Forum 1.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
by t0pP8uZz
CVE-2008-1307 EXPLOITDB html VERIFIED
Kingsoft Antivirus Online Update Module - Memory Corruption
Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 2007.12.29.29 allows remote attackers to execute arbitrary code via a long argument to the SetUninstallName method.
by void
EIP-2026-118847 EXPLOITDB html VERIFIED
Microsoft Internet Explorer 7 - Combined JavaScript and XML Remote Information Disclosure
by Ronald van den Heetkamp
CVE-2008-7136 EXPLOITDB html VERIFIED
Icq Toolbar - Improper Input Validation
toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a long argument to the (1) RequestURL, (2) GetPropertyById, or (3) SetPropertyById method, different vectors than CVE-2008-7135.
by spdr
CVE-2008-1208 EXPLOITDB html VERIFIED
Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x - XSS
Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbitrary web script or HTML via the user parameter.
by Henri Lindberg
CVE-2008-0986 EXPLOITDB html VERIFIED
Google Android SDK < m3-rc37a - Numeric Error
Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier, and m5-rc14, allows remote attackers to execute arbitrary code via a crafted BMP file with a header containing a negative offset field.
by Alfredo Ortega
CVE-2007-6016 EXPLOITDB html VERIFIED
Symantec Backup Exec for Windows Server <12.0.1364 - Buffer Overflow
Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the scheduler component in the Media Server in Symantec Backup Exec for Windows Server (BEWS) 11d 11.0.6235 and 11.0.7170, and 12.0 12.0.1364, allow remote attackers to execute arbitrary code via a long (1) _DOWText0, (2) _DOWText1, (3) _DOWText2, (4) _DOWText3, (5) _DOWText4, (6) _DOWText5, (7) _DOWText6, (8) _MonthText0, (9) _MonthText1, (10) _MonthText2, (11) _MonthText3, (12) _MonthText4, (13) _MonthText5, (14) _MonthText6, (15) _MonthText7, (16) _MonthText8, (17) _MonthText9, (18) _MonthText10, or (19) _MonthText11 property value when executing the Save method. NOTE: the vendor states "Authenticated user involvement required," but authentication is not needed to attack a client machine that loads this control.
by Elazar
CVE-2008-1044 EXPLOITDB html VERIFIED
Move Networks Move Media Player - Memory Corruption
Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QSP2IE) in qsp2ie07076007.dll 7.7.6.7 and qsp2ie07074039.dll 7.7.4.39 in Move Media Player allows remote attackers to execute arbitrary code via a long argument to the UploadLogs method, a different vector than CVE-2007-4722. NOTE: some of these details are obtained from third party information.
by Elazar
CVE-2008-4771 EXPLOITDB html VERIFIED
4xem Vatctrl Class - Memory Corruption
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 and 1.0.0.51), (2) D-Link MPEG4 SHM Audio Control (VAPGDecoder.dll 1.7.0.5), (3) Vivotek RTSP MPEG4 SP Control (RtspVapgDecoderNew.dll 2.0.0.39), and possibly other products, allows remote attackers to execute arbitrary code via a long Url property. NOTE: some of these details are obtained from third party information.
by rgod
CVE-2008-1116 EXPLOITDB html VERIFIED
Rising Antivirus Online Scanner - RCE
Insecure method vulnerability in the Web Scan Object ActiveX control (OL2005.dll) in Rising Antivirus Online Scanner allows remote attackers to force the download and execution of arbitrary code by setting the BaseURL property and invoking the UpdateEngine method. NOTE: some of these details are obtained from third party information.
by John Smith
CVE-2008-0911 EXPLOITDB html VERIFIED
Iscripts Multicart - SQL Injection
SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.
by t0pP8uZz
CVE-2008-7222 EXPLOITDB html VERIFIED
RunCMS 1.6.1 - XSS
Cross-site scripting (XSS) vulnerability in system/admin.php in RunCMS 1.6.1 allows remote attackers to inject arbitrary web script or HTML via the rank_title parameter in a RankForumAdd action.
by NBBN
CVE-2007-4474 EXPLOITDB html VERIFIED
IBM Lotus Domino - Buffer Overflow
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.
by Elazar
CVE-2008-5711 EXPLOITDB html VERIFIED
Facebook PhotoUploader <5.0.14.0 - Buffer Overflow
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a long FileMask property value.
by MC Group Ltd.
CVE-2006-6334 EXPLOITDB html VERIFIED
Citrix Presentation Server Client <9.230 - Buffer Overflow
Heap-based buffer overflow in the SendChannelData function in wfica.ocx in Citrix Presentation Server Client before 9.230 for Windows allows remote malicious web sites to execute arbitrary code via a DataSize parameter that is less than the length of the Data buffer.
by Elazar
CVE-2008-0748 EXPLOITDB html VERIFIED
Sony Axruploadserver Activex Control - Memory Corruption
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging method. NOTE: some of these details are obtained from third party information.
by Elazar
EIP-2026-118782 EXPLOITDB html VERIFIED
Microsoft DirectSpeechSynthesis Module - Remote Buffer Overflow
by rgod
CVE-2008-0748 EXPLOITDB html VERIFIED
Sony Axruploadserver Activex Control - Memory Corruption
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging method. NOTE: some of these details are obtained from third party information.
by Trancek
CVE-2008-0457 EXPLOITDB html VERIFIED
Symantec Backupexec System Recovery - Improper Input Validation
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, as used by Symantec Backup Exec System Recovery Manager 7.0 and 7.0.1, allows remote attackers to upload and execute arbitrary JSP files via unknown vectors.
by titon
EIP-2026-118608 EXPLOITDB html VERIFIED
GlobalLink 2.6.1.2 - 'HanGamePlugincn18.dll' ActiveX Control Multiple Buffer Overflow Vulnerabilities
by anonymous