Exploitdb Exploits

4,733 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-102733 EXPLOITDB python
Rough Auditing Tool for Security (RATS) 2.3 - Array Out of Block Crash
by David Silveiro
CVE-2015-9222 EXPLOITDB HIGH python
Qualcomm Msm8909w Firmware - Resource Management Error
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, SD 845, SDM630, SDM636, SDM660, and Snapdragon_High_Med_2016, processing erroneous bitstreams may result in a HW freeze. FW should detect the HW freeze based on watchdog timer, but because the watchdog timer is not enabled, an infinite loop occurs, resulting in a device freeze.
by Milad Doorbash
CVSS 7.5
CVE-2016-20041 EXPLOITDB HIGH python
Yasr 0.6.9-5 Buffer Overflow via Command-line Parameter
Yasr 0.6.9-5 contains a buffer overflow vulnerability that allows local attackers to crash the application or execute arbitrary code by supplying an oversized argument to the -p parameter. Attackers can invoke yasr with a crafted payload containing junk data, shellcode, and a return address to overwrite the stack and trigger code execution.
by Juan Sacco
CVSS 8.4
EIP-2026-102734 EXPLOITDB python
Rough Auditing Tool for Security (RATS) 2.3 - Crash (PoC)
by David Silveiro
EIP-2026-101751 EXPLOITDB python
Gemtek CPE7000 / WLTCS-106 - Multiple Vulnerabilities
by Federico Ramondino
CVE-2016-20040 EXPLOITDB HIGH python
TiEmu 3.03-nogdb+dfsg-3 Buffer Overflow via ROM Parameter
TiEmu 3.03-nogdb+dfsg-3 contains a buffer overflow vulnerability in the ROM parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized ROM parameter to the tiemu command-line interface to overflow the stack buffer and overwrite the instruction pointer with malicious addresses.
by Juan Sacco
CVSS 8.4
CVE-2016-0491 EXPLOITDB python VERIFIED
Oracle Application Testing Suite - Unspecified Vuln
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect integrity and availability via unknown vectors related to Load Testing for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that the UploadFileAction servlet allows remote authenticated users to upload and execute arbitrary files via an * (asterisk) character in the fileType parameter.
by Zhou Yu
CVE-2016-0492 EXPLOITDB python VERIFIED
Oracle Application Testing Suite - Info Disclosure
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0488. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function, which allows remote attackers to bypass authentication via directory traversal sequences following a URI entry that does not require authentication, as demonstrated by olt/Login.do/../../olt/UploadFileUpload.do.
by Zhou Yu
EIP-2026-117148 EXPLOITDB python
Express Zip 2.40 - Directory Traversal
by R-73eN
CVE-2016-20039 EXPLOITDB HIGH python
Multi Emulator Super System 0.154-3.1 Buffer Overflow
Multi Emulator Super System 0.154-3.1 contains a buffer overflow vulnerability in the gamma parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized gamma parameter value to overflow the stack buffer and overwrite the instruction pointer with a controlled address to achieve code execution.
by Juan Sacco
CVSS 8.4
CVE-2016-2087 EXPLOITDB HIGH python
Hexchat - Path Traversal
Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in the server name.
by PizzaHatHacker
CVSS 7.4
CVE-2016-2233 EXPLOITDB HIGH python
Hexchat - Memory Corruption
Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC servers to cause a denial of service (crash) via a large number of options in a CAP LS message.
by PizzaHatHacker
CVSS 7.5
CVE-2016-2345 EXPLOITDB CRITICAL python
Dameware Mini Remote Control - Memory Corruption
Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string.
by Securifera
CVSS 9.8
EIP-2026-113543 EXPLOITDB python VERIFIED
WordPress Plugin Advanced Video 1.0 - Local File Inclusion
by evait security GmbH
EIP-2026-116379 EXPLOITDB python
TallSoft SNMP/TFTP Server 1.0.0 - Denial of Service
by Charley Celice
CVE-2025-34036 EXPLOITDB CRITICAL python
TVT White-Labeled DVR - Command Injection
An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service called "Cross Web Server" that listens on TCP ports 81 and 82. The web interface fails to sanitize input in the URI path passed to the language extraction functionality. When the server processes a request to /language/[lang]/index.html, it uses the [lang] input unsafely in a tar extraction command without proper escaping. This allows an unauthenticated remote attacker to inject shell commands and achieve arbitrary command execution as root. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-06 UTC.
by K1P0D
CVSS 9.8
EIP-2026-119201 EXPLOITDB python
Sysax Multi Server 6.50 - HTTP File Share Overflow Remote Code Execution (SEH)
by Paul Purcell
EIP-2026-117335 EXPLOITDB python VERIFIED
Internet Download Manager 6.25 Build 14 - 'Find file' Unicode (SEH)
by Rakan Alotaibi
CVE-2016-3115 EXPLOITDB MEDIUM python
OpenSSH <7.2p2 - CRLF Injection
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data, related to the (1) do_authenticated1 and (2) session_x11_req functions.
by tintinweb
CVSS 6.4
CVE-2014-6278 EXPLOITDB HIGH python
GNU Bash <4.3 - RCE
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.
by thatchriseckert
CVSS 8.8
EIP-2026-116666 EXPLOITDB python
Zortam Mp3 Media Studio 20.15 - Overflow (PoC) (SEH)
by INSECT.B
CVE-2016-2851 EXPLOITDB CRITICAL python
Debian Linux < 4.1.0 - Memory Corruption
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-based buffer overflow.
by X41 D-Sec GmbH
CVSS 9.8
CVE-2014-1767 EXPLOITDB python
Microsoft Windows - Privilege Escalation
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."
by Rick Larabee
EIP-2026-116135 EXPLOITDB python
Quick Tftp Server Pro 2.3 - Read Mode Denial of Service
by Guillaume Kaddouch
EIP-2026-115299 EXPLOITDB python
FreeProxy Internet Suite 4.10 - Denial of Service
by Guillaume Kaddouch