Perl Exploits
2,849 exploits tracked across all sources.
Meteor FTP Server 1.2/1.5 - USER Memory Corruption
by zerash
IBM DB2 <8.1 - Privilege Escalation
IBM DB2 7.1 and 8.1 allow the bin user to gain root privileges by modifying the shared libraries that are used in setuid root programs.
EveryBuddy 0.4.3 - Long Message Denial of Service
by Noam Rathaus
Postfix <= 1.1.12 - Denial of Service via Malformed Envelope Address
The address parser code in Postfix 1.1.12 and earlier allows remote attackers to cause a denial of service (lock) via (1) a malformed envelope address to a local host that would generate a bounce and contains the ".!" string in the MAIL FROM or Errors-To headers, which causes nqmgr to lock up, or (2) via a valid MAIL FROM with a RCPT TO containing a ".!" string, which causes an instance of the SMTP listener to lock up.
wu-ftpd 2.5.0-2.6.2 - Remote Code Execution via fb_realpath Off-by-one Error
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to execute arbitrary code, as demonstrated in wu-ftpd 2.5.0 through 2.6.2 via commands that cause pathnames of length MAXPATHLEN+1 to trigger a buffer overflow, including (1) STOR, (2) RETR, (3) APPE, (4) DELE, (5) MKD, (6) RMD, (7) STOU, or (8) RNTO.
CVSS 9.8
Cisco IOS - Denial of Service via Malformed URL
The web server for Cisco Aironet AP1x00 Series Wireless devices running certain versions of IOS 12.2 allow remote attackers to cause a denial of service (reload) via a malformed URL.
by blackangels
GNU GNATS 3.113.1_6 - Queue-PR Database Command Line Option Buffer Overflow
by inv[at]dtors
IglooFTP PRO 3.8 - Remote Code Execution via Long FTP Banner or Command Response
Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP banner, or long responses to the client commands (2) USER, (3) PASS, (4) ACCT, and possibly other commands.
by inv[at]dtors
VP-ASP - SQL Injection via id Parameter
SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.
by Bosen & TioEuy
VP-ASP - SQL Injection via id Parameter
SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the id parameter.
by TioEuy & AresU
Twilight Webserver 1.3.3.0 - Denial of Service via Long URI GET Request
Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request for a long URI, a different vulnerability than CVE-2004-2376.
by anonymous
Macromedia ColdFusion MX 6.0 - Remote Development Service File Disclosure
by rs2112
Adobe Acrobat Reader < 5.0.7 - Remote Code Execution via Long Mailto Link
Buffer overflow in the WWWLaunchNetscape function of Adobe Acrobat Reader (acroread) 5.0.7 and earlier allows remote attackers to execute arbitrary code via a .pdf file with a long mailto link.
by Paul Szabo
Foxweb <2.5 - Remote Code Execution
Buffer overflow in (1) foxweb.dll and (2) foxweb.exe of Foxweb 2.5 allows remote attackers to execute arbitrary code via a long URL (PATH_INFO value).
by pokleyzz
gkrellm 2.1.x - Remote Code Execution via Buffer Overflow in gkrellmd
Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
by dodo
gkrellm 2.1.x - Remote Code Execution via Buffer Overflow in gkrellmd
Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
by dodo
phpBB < 2.0.5 - SQL Injection via viewtopic.php topic_id Parameter
SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.
by Rick Patel
PostgreSQL <1.2.9rc1 - SQL Injection
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allows remote attackers to execute arbitrary SQL and gain privileges by bypassing authentication or stealing passwords via the USER name.
by Spaine
Mailtraq 2.1.0.1302 - User Password Encoding
by Noam Rathaus
mnogosearch 3.2.10 - Remote Code Execution via Long tmplt Parameter
Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt parameter.
by pokleyzz
Mandrake Linux 8.2 - '/usr/mail' Local Overflow
by anonymous
By Source