Exploitdb Exploits
2,809 exploits tracked across all sources.
Adobe Acrobat Reader < 5.0.7 - Remote Code Execution via Long Mailto Link
Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.
by Paul Szabo
Foxweb <2.5 - Remote Code Execution
Buffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL (PATH_INFO value).
by pokleyzz
gkrellm 2.1.x - Remote Code Execution via Buffer Overflow in gkrellmd
Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
by dodo
gkrellm 2.1.x - Remote Code Execution via Buffer Overflow in gkrellmd
Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
by dodo
phpBB < 2.0.5 - SQL Injection via viewtopic.php topic_id Parameter
SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.
by Rick Patel
PostgreSQL <1.2.9rc1 - SQL Injection
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.
by Spaine
Mailtraq 2.1.0.1302 - User Password Encoding
by Noam Rathaus
mnogosearch 3.2.10 - Remote Code Execution via Long tmplt Parameter
Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt parameter.
by pokleyzz
Mandrake Linux 8.2 - '/usr/mail' Local Overflow
by anonymous
mnogosearch 3.1.20 - Remote Code Execution via Long ul Parameter
Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter.
by inv
mnogosearch 3.1.20 - Remote Code Execution via Long ul Parameter
Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul parameter.
by pokleyzz
Apache HTTP Server 2.0.37-2.0.45 - Denial of Service and Possible Remote Code Execution via Long Strings in apr_psprintf
Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long strings, as demonstrated using XML objects to mod_dav, and possibly other vectors.
by Matthew Murphy
Microsoft Internet Explorer <6.0 - RCE
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via / (slash) characters in the Type property of an Object tag in a web page.
by alumni
ATFTP 0.7 - Timeout Command Line Argument Local Buffer Overflow
by Julien LANTHEA
KON kon2 <0.3.9b - Remote Code Execution
Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command line argument.
by wsxz
Webfroot Shoutbox 2.32 - 'Expanded.php' Remote Command Execution
by _6mO_HaCk
IBM AIX 4.3.3 - Buffer Overflow in lsmcode
Buffer overflow in lsmcode in AIX 4.3.3.
by watercloud
WebCortex WebStores 2000 6.0 - SQL Injection via Search_Text Parameter
SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthorized access and execute arbitrary commands via the Search_Text parameter.
by Bosen
RedHat 9.0 / Slackware 8.1 - '/bin/mail' Carbon Copy Field Buffer Overrun
IBM AIX 4.3.3 - Local Privilege Escalation via GNU make CC Argument Buffer Overflow
Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long CC argument.
by watercloud
IBM AIX 5.1-5.2 - Local Privilege Escalation via LVM putlvcb/getlvcb Buffer Overflow
Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) getlvcb commands.
by watercloud
Webfroot Shoutbox 2.32 - Remote Command Execution
by pokleyzz
Webfroot Shoutbox < 2.32 (Apache) - Local File Inclusion / Remote Code Execution
by anonymous
IBM AIX - Privilege Escalation via Symlink Attack on Inventory Scout Daemon Log File
The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a command line argument (log file). NOTE: this might be related to CVE-2006-5002.
by watercloud
By Source