Exploitdb Exploits

4,733 exploits tracked across all sources.

Sort: Activity Stars
CVE-2011-0923 EXPLOITDB python
HP Data Protector - Improper Input Validation
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."
by Alessandro Di Pinto & Claudio Moletta
CVE-2010-2620 EXPLOITDB python VERIFIED
Open-ftpd < 1.2 - Authentication Bypass
Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or other commands without performing the required login steps first.
by Wireghoul
CVE-2013-6079 EXPLOITDB python VERIFIED
Mostgear Easy Lan Folder Share - Memory Corruption
Buffer overflow in MostGear Soft Easy LAN Folder Share 3.2.0.100 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in the (1) registration code field in the activate license window or the (2) HKLM\SOFTWARE\MostGear\EasyLanFolderShare_V1\License registry key. NOTE: it is not clear from the original report whether this issue crosses privilege boundaries. If not, then it should not be included in CVE.
by sagi-
CVE-2013-4730 EXPLOITDB python VERIFIED
PCMan's FTP Server 2.0.7 - RCE
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command.
by Ottomatik
EIP-2026-115202 EXPLOITDB python VERIFIED
EchoVNC Viewer - Remote Denial of Service
by Z3r0n3
CVE-2013-3956 EXPLOITDB python VERIFIED
Novell Client - Access Control
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows Server 2008; and Novell Client 2 SP3 on Windows Server 2008 R2, Windows 7, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted 0x143B6B IOCTL call.
by sickness
EIP-2026-102517 EXPLOITDB python
OpenEMM-2013 8.10.380.hf13.0.066 - SOAP SQL Injection / Persistent Cross-Site Scripting
by drone
CVE-2013-4659 EXPLOITDB CRITICAL python
Broadcom ACSD - RCE
Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU.
by Jacob Holcomb
CVSS 9.8
CVE-2013-0699 EXPLOITDB python
Galil RIO-47100 Pocket PLC - DoS
The Galil RIO-47100 Pocket PLC allows remote attackers to cause a denial of service via a session that includes "repeated requests."
by Sapling
CVE-2013-4890 EXPLOITDB python
Samsung PS50C7700 - DoS
The DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon crash) via a long URI to TCP port 5600.
by Malik Mesellem
CVE-2014-2671 EXPLOITDB python
Microsoft Windows Media Player 11.0.5721.5230 - Memory Corruption
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted WAV file.
by ariarat
EIP-2026-115554 EXPLOITDB python VERIFIED
Light Audio Mixer 1.0.12 - '.wav' Crash (PoC)
by ariarat
EIP-2026-115514 EXPLOITDB python VERIFIED
Kate's Video Toolkit 7.0 - '.wav' Crash (PoC)
by ariarat
CVE-2013-2739 EXPLOITDB CRITICAL python VERIFIED
MiniDLNA - Buffer Overflow
MiniDLNA has heap-based buffer overflow
by Zachary Cutlip
CVSS 9.8
CVE-2013-2784 EXPLOITDB python
Triangle Research International Nano-10 PLC <r81 - DoS
Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bounds checking of data in Modbus/TCP packets, which allows remote attackers to cause a denial of service (networking outage) via a crafted packet to TCP port 502.
by Sapling
CVE-2013-5019 EXPLOITDB python VERIFIED
Ultra Mini HTTPD 1.21 - Buffer Overflow
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resource name in an HTTP request.
by superkojiman
EIP-2026-115494 EXPLOITDB python
Jolix Media Player 1.1.0 - '.m3u' Denial of Service
by IndonesiaGokilTeam
CVE-2013-2729 EXPLOITDB CRITICAL python
Adobe Reader/Acrobat <9.5.5, <10.1.7, <11.0.03 - RCE
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.
by feliam
CVSS 9.8
EIP-2026-116167 EXPLOITDB python
Realtek Sound Manager AvRack - '.wav' Crash (PoC)
by Asesino04
CVE-2013-4743 EXPLOITDB CRITICAL python
Static HTTP Server 1.0 - Buffer Overflow
Static HTTP Server 1.0 has a Local Overflow
by Jacob Holcomb
CVSS 9.8
EIP-2026-116735 EXPLOITDB python VERIFIED
Adrenalin Player 2.2.5.3 - '.wvx' Local Buffer Overflow (SEH)
by MrXors
EIP-2026-116487 EXPLOITDB python VERIFIED
VideoLAN VLC Media Player 2.0.7 - '.png' Crash (PoC)
by Kevin Fujimoto
EIP-2026-114965 EXPLOITDB python
AVS Media Player 4.1.11.100 - '.ac3' Denial of Service
by metacom
EIP-2026-105669 EXPLOITDB python
C.P.Sub 4.5 - Authentication Bypass
by Chako
EIP-2026-103466 EXPLOITDB python VERIFIED
FileCOPA FTP Server - Remote Denial of Service
by Chako