Exploitdb Exploits

4,733 exploits tracked across all sources.

Sort: Activity Stars
CVE-2011-3478 EXPLOITDB python VERIFIED
Symantec pcAnywhere <12.5.3 - RCE
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), does not properly filter login and authentication data, which allows remote attackers to execute arbitrary code via a crafted session on TCP port 5631.
by S2 Crew
CVE-2011-4222 EXPLOITDB python VERIFIED
Investintech.com Able2Extract - DoS/Code Injection
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.
by Carlos Mario Penagos Hollmann
CVE-2012-1830 EXPLOITDB python VERIFIED
Wellintech Kingview < 6.53 - Memory Corruption
Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 555.
by Carlos Mario Penagos Hollmann
CVE-2011-4222 EXPLOITDB python VERIFIED
Investintech.com Able2Extract - DoS/Code Injection
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.
by Carlos Mario Penagos Hollmann
CVE-2011-4222 EXPLOITDB python VERIFIED
Investintech.com Able2Extract - DoS/Code Injection
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document.
by Carlos Mario Penagos Hollmann
EIP-2026-117986 EXPLOITDB python VERIFIED
Sysax 5.62 - Admin Interface Local Buffer Overflow
by Craig Freyman
CVE-2011-0922 EXPLOITDB python VERIFIED
HP Data Protector - Improper Input Validation
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share pathname.
by Ben Turner
EIP-2026-118529 EXPLOITDB python VERIFIED
EZHomeTech Ezserver 6.4 - Remote Stack Overflow
by modpr0be
EIP-2026-116424 EXPLOITDB python VERIFIED
Total Video Player 1.31 - '.m3u' Crash (PoC)
by 0dem
EIP-2026-112932 EXPLOITDB python VERIFIED
Useresponse 1.0.2 - Privilege Escalation / Remote Code Execution
by mr_me
CVE-2007-1195 EXPLOITDB python VERIFIED
XM Easy Personal FTP Server 5.3.0 - Buffer Overflow
Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unspecified vectors. NOTE: this issue might overlap CVE-2006-2225, CVE-2006-2226, or CVE-2006-5728.
by mr_me
EIP-2026-111610 EXPLOITDB python VERIFIED
qdPM 7 - Arbitrary File upload
by loneferret
CVE-2012-0780 EXPLOITDB python
Adobe Illustrator < CS6 - Memory Corruption
Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.
by Felipe Andres Manzano
EIP-2026-101262 EXPLOITDB python VERIFIED
Edimax IC-3030iWn - UDP Packet Password Information Disclosure
by y3dips
CVE-2012-0677 EXPLOITDB python VERIFIED
Apple iTunes <10.6.3 - Buffer Overflow
Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted .m3u playlist.
by LiquidWorm
CVE-2012-2122 EXPLOITDB python VERIFIED
Oracle Mysql - Authentication Bypass
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x before 5.1.62, 5.2.x before 5.2.12, 5.3.x before 5.3.6, and 5.5.x before 5.5.23, when running in certain environments with certain implementations of the memcmp function, allows remote attackers to bypass authentication by repeatedly authenticating with the same incorrect password, which eventually causes a token comparison to succeed due to an improperly-checked return value.
by David Kennedy (ReL1K)
CVE-2012-1493 EXPLOITDB python VERIFIED
F5 Big-ip 3600 - Credentials Management
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, and Enterprise Manager before 2.1.0-HF2, 2.2.x before 2.2.0-HF1, and 2.3.x before 2.3.0-HF3, use a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins via the PubkeyAuthentication option.
by David Kennedy (ReL1K)
EIP-2026-110914 EXPLOITDB python VERIFIED
phpAcounts 0.5.3 - SQL Injection
by loneferret
CVE-2012-2915 EXPLOITDB python VERIFIED
Lattice Semiconductor PAC-Designer <6.2.1344 - Buffer Overflow
Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary code via a long string in a Value tag in a SymbolicSchematicData definition tag in PAC Design (.pac) file.
by b33f
EIP-2026-114948 EXPLOITDB python VERIFIED
Audio Editor Master 5.4.1.217 - Denial of Service
by Onying
EIP-2026-105474 EXPLOITDB python VERIFIED
Bigware Shop 2.1x - 'main_bigware_54.php' SQL Injection
by rwenzel
EIP-2026-116279 EXPLOITDB python
Sorensoft Power Media 6.0 - Denial of Service
by Onying
EIP-2026-113407 EXPLOITDB python VERIFIED
WHMCompleteSolution (WHMCS) - 'boleto_bb.php' SQL Injection
by dex
CVE-2012-0297 EXPLOITDB python VERIFIED
Symantec Web Gateway <5.0.3 - RCE
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers to execute arbitrary code by (1) injecting crafted data or (2) including crafted data.
by muts
CVE-2007-5762 EXPLOITDB python VERIFIED
Novell Netware Client - Improper Input Validation
NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by opening the \\.\nicm device and providing crafted kernel addresses via IOCTLs with the METHOD_NEITHER buffering mode.
by sickness