Exploitdb Exploits

4,733 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-118904 EXPLOITDB python VERIFIED
MinaliC WebServer 2.0.0 - Remote Buffer Overflow
by superkojiman
CVE-2013-3535 EXPLOITDB python
Themelogik Cmslogik - XSS
Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_email, (2) header_title, (3) site_title parameter to admin/settings; (4) recaptcha_private or (5) recaptcha_public parameter to admin/captcha_settings; (6) fb_appid, (7) fp_secret, (8) tw_consumer_key, or (9) tw_consumer_secret parameter to admin/social_settings; (10) slug parameter to admin/gallery/save_item_settings; or (11) item_link parameter to admin/edit_menu_item_ajax. NOTE: this issue might be resultant from CSRF.
by LiquidWorm
CVE-2006-6184 EXPLOITDB python VERIFIED
Alliedtelesyn At-tftp < 1.9 - Buffer Overflow
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long filename in a (1) GET or (2) PUT command.
by xis_one
EIP-2026-118582 EXPLOITDB python VERIFIED
Freefloat FTP Server 1.0 - DEP Bypass with ROP
by negux
EIP-2026-118320 EXPLOITDB python VERIFIED
BigAnt Server 2.97 - DDNF 'Username' Remote Buffer Overflow
by Craig Freyman
EIP-2026-117270 EXPLOITDB python VERIFIED
HexChat 2.9.4 - Local Overflow
by Matt Andreko
EIP-2026-116056 EXPLOITDB python VERIFIED
Personal File Share 1.0 - Denial of Service
by npn
EIP-2026-115188 EXPLOITDB python VERIFIED
Easy DVD Player 3.5.1 - libav 'libavcodec_plugin.dll' Denial of Service
by metacom
EIP-2026-118325 EXPLOITDB python VERIFIED
BlazeVideo HDTV Player Standard - '.plf' File Remote Buffer Overflow
by metacom
EIP-2026-115942 EXPLOITDB python VERIFIED
Nitro Pro 8.0.3.1 - Crash (PoC)
by John Cobb
EIP-2026-114882 EXPLOITDB python VERIFIED
aktiv-player 2.9.0 - Crash (PoC)
by metacom
EIP-2026-119104 EXPLOITDB python VERIFIED
Sami FTP Server 2.0.1 - 'LIST' Buffer Overflow
by superkojiman
CVE-2013-7280 EXPLOITDB python VERIFIED
HansoTools Hanso Player <2.5.0 - Buffer Overflow
Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of service (crash) via a long string in a .m3u file.
by metacom
CVE-2010-3333 EXPLOITDB HIGH python VERIFIED
Microsoft Office - Buffer Overflow
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via crafted RTF data, aka "RTF Stack Buffer Overflow Vulnerability."
by g11tch
CVSS 7.8
EIP-2026-117764 EXPLOITDB python VERIFIED
Photodex ProShow Producer 5.0.3297 - '.pxs' Memory Corruption
by Julien Ahrens
EIP-2026-118573 EXPLOITDB python VERIFIED
Freefloat FTP Server 1.0 - 'Raw' Remote Buffer Overflow
by superkojiman
CVE-2013-0249 EXPLOITDB python
Haxx Curl - Memory Corruption
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the realm parameter in a (1) POP3, (2) SMTP or (3) IMAP message.
by Volema
CVE-2013-0658 EXPLOITDB python VERIFIED
Schneider Electric Accutech Manager <2.00.1 - Buffer Overflow
Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remote attackers to execute arbitrary code via a crafted HTTP request.
by Evren Yalçın
EIP-2026-104475 EXPLOITDB python VERIFIED
Verax NMS - Multiple Method Authentication Bypass
by Andrew Brooks
EIP-2026-114916 EXPLOITDB python VERIFIED
Apple Quick Time Player (Windows) 7.7.3 - Out of Bound Read
by Debasish Mandal
EIP-2026-104454 EXPLOITDB python VERIFIED
SQLiteManager 1.2.4 - Remote PHP Code Injection
by RealGame
EIP-2026-116235 EXPLOITDB python VERIFIED
Serva 2.0.0 - HTTP Server GET Remote Denial of Service
by Julien Ahrens
EIP-2026-116234 EXPLOITDB python VERIFIED
Serva 2.0.0 - DNS Server QueryName Remote Denial of Service
by Julien Ahrens
CVE-2012-6096 EXPLOITDB python VERIFIED
Nagios < 3.4.3 - Memory Corruption
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.
by blasty
EIP-2026-101005 EXPLOITDB python
Colloquy 1.3.5/1.3.6 - Denial of Service
by UberLame