Exploitdb Exploits

4,733 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-118453 EXPLOITDB python VERIFIED
Easy Address Book Web Server 1.6 - Remote Stack Buffer Overflow
by superkojiman
CVE-2014-0242 EXPLOITDB HIGH python VERIFIED
mod_wsgi <3.4 - Info Disclosure
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.
by Buck Golemon
CVSS 7.5
CVE-2007-6483 EXPLOITDB python VERIFIED
SafeNet Sentinel Protection Server <7.4.0 - Path Traversal
Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.0.0 through 7.4.0 and possibly earlier versions, and Sentinel Keys Server 1.0.3 and possibly earlier versions, allows remote attackers to read arbitrary files via a .. (dot dot) in the query string.
by Matt Schmidt
CVE-2013-2118 EXPLOITDB python
SPIP <3.0.9, <2.1.22, <2.0.23 - Privilege Escalation
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.
by Gregory Draperi
CVE-2014-5116 EXPLOITDB python VERIFIED
Cairo - Denial of Service
The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a large string.
by Osanda Malith Jayathissa
CVE-2014-3212 EXPLOITDB python VERIFIED
Intel Indeo - Video Memory Corruption
by Aryan Bayaninejad
CVE-2014-3736 EXPLOITDB python VERIFIED
ALLPlayer - '.wav' File Processing Memory Corruption
by Aryan Bayaninejad
CVE-2014-3444 EXPLOITDB python VERIFIED
Realnetworks Realplayer < 16.0.3.51 - Code Injection
The GetGUID function in codecs/dmp4.dll in RealNetworks RealPlayer 16.0.3.51 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (write access violation and application crash) via a malformed .3gp file.
by Aryan Bayaninejad
CVE-2014-3791 EXPLOITDB python VERIFIED
Efssoft Easy File Sharing Web Server - Memory Corruption
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code via a long string in a cookie UserID parameter to vfolder.ghp.
by superkojiman
CVE-2004-2466 EXPLOITDB python VERIFIED
Easy Chat Server <2.2 - DoS
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.
by superkojiman
CVE-2014-3443 EXPLOITDB python VERIFIED
Jetaudio < 8.1.1 - Memory Corruption
JetMPAd.ax in JetAudio 8.1.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file.
by Aryan Bayaninejad
CVE-2014-3216 EXPLOITDB python VERIFIED
Gomlab Gom Media Player < 2.2.57.5189 - Improper Input Validation
GOM Media Player 2.2.57.5189 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg file.
by Aryan Bayaninejad
CVE-2014-3441 EXPLOITDB python VERIFIED
Videolan Vlc Media Player - Memory Corruption
codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash) via a crafted .png file, as demonstrated by a png in a .wave file.
by Aryan Bayaninejad
EIP-2026-103863 EXPLOITDB python VERIFIED
AssistMyTeam Team Helpdesk - Multiple Information Disclosure Vulnerabilities
by bhamb
EIP-2026-105201 EXPLOITDB python VERIFIED
ApPHP MicroBlog 1.0.1 - Remote Command Execution
by LOTFREE
CVE-2014-4158 EXPLOITDB python VERIFIED
Kolibri 2.0 - Buffer Overflow
Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET request.
by Polunchis
CVE-2014-2994 EXPLOITDB python
Acunetix Web Vulnerability Scanner - Memory Corruption
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to execute arbitrary code via an HTML file containing an IMG element with a long URL (src attribute).
by An7i
EIP-2026-105582 EXPLOITDB python
Bonefire 0.7.1 - Reinstall Admin Account
by Mehmet Ince
CVE-2010-5300 EXPLOITDB python VERIFIED
Jzip <2.0.0.132900 - Buffer Overflow
Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name in a zip archive.
by motaz reda
EIP-2026-103722 EXPLOITDB python
WhatsApp < 2.11.7 - Remote Crash
by Jaime Sánchez
CVE-2014-0160 EXPLOITDB HIGH python VERIFIED
OpenSSL <1.0.1g - Info Disclosure
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
by Fitzl Csaba
CVSS 7.5
CVE-2014-0346 EXPLOITDB python VERIFIED
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0160. Reason: This candidate is a reservation duplicate of CVE-2014-0160. Notes: All CVE users should reference CVE-2014-0160 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
by Fitzl Csaba
CVE-2014-0160 EXPLOITDB HIGH python VERIFIED
OpenSSL <1.0.1g - Info Disclosure
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
by Jared Stafford
CVSS 7.5
CVE-2014-0346 EXPLOITDB python VERIFIED
Rejected
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0160. Reason: This candidate is a reservation duplicate of CVE-2014-0160. Notes: All CVE users should reference CVE-2014-0160 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
by Jared Stafford
EIP-2026-115177 EXPLOITDB python VERIFIED
EagleGet 1.1.8.1 - Denial of Service
by Interference Security