Exploitdb Exploits

4,733 exploits tracked across all sources.

Sort: Activity Stars
CVE-2011-0922 EXPLOITDB python VERIFIED
HP Data Protector - Improper Input Validation
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that references a UNC share pathname.
by fdiskyou
CVE-2011-0923 EXPLOITDB python VERIFIED
HP Data Protector - Improper Input Validation
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."
by fdiskyou
EIP-2026-105932 EXPLOITDB python VERIFIED
Clipbucket 2.4 RC2 645 - SQL Injection
by AutoSec Tools
EIP-2026-103973 EXPLOITDB python VERIFIED
Lumension Security Lumension Device Control 4.x - Memory Corruption
by Andy Davis
EIP-2026-115819 EXPLOITDB python VERIFIED
Microsoft Windows Vista/2008 - 'nsiproxy.sys' Local Kernel Denial of Service
by Lufeng Li
EIP-2026-117932 EXPLOITDB python VERIFIED
Sonique 1.96 - '.m3u' Local Buffer Overflow
by sinfulsecurity
EIP-2026-116994 EXPLOITDB python VERIFIED
CoolPlayer Portable 2.19.2 - Local Buffer Overflow
by sinfulsecurity
EIP-2026-116335 EXPLOITDB python
Steam Software - Denial of Service
by david.r.klein
EIP-2026-111250 EXPLOITDB python VERIFIED
phpWebSite 1.7.1 - 'upload.php' Arbitrary File Upload
by AutoSec Tools
EIP-2026-107393 EXPLOITDB python VERIFIED
Getsimple CMS 3.0 - 'set' Local File Inclusion
by AutoSec Tools
CVE-2011-10022 EXPLOITDB HIGH python VERIFIED
SPlayer <3.7 - Buffer Overflow
SPlayer version 3.7 and earlier is vulnerable to a stack-based buffer overflow when processing HTTP responses containing an overly long Content-Type header. The vulnerability occurs due to improper bounds checking on the header value, allowing an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code. Exploitation requires the victim to open a media file that triggers an HTTP request to a malicious server, which responds with a crafted Content-Type header.
by xsploitedsec
EIP-2026-104077 EXPLOITDB python VERIFIED
sipdroid 2.2 - SIP INVITE Response User Enumeration
by Anibal Vaz Marques
CVE-2011-0978 EXPLOITDB python VERIFIED
Microsoft Excel - Memory Corruption
Stack-based buffer overflow in Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via vectors related to an axis properties record, and improper incrementing of an array index, aka "Excel Array Indexing Vulnerability."
by webDEViL
CVE-2011-10025 EXPLOITDB HIGH python VERIFIED
Subtitle Processor 7.7.1 - Buffer Overflow
Subtitle Processor 7.7.1 contains a buffer overflow vulnerability in its .m3u file parser. When a crafted playlist file is opened, the application converts input to Unicode and copies it to a fixed-size stack buffer without proper bounds checking. This allows an attacker to overwrite the Structured Exception Handler (SEH) and execute arbitrary code.
by Brandon Murphy
EIP-2026-114942 EXPLOITDB python VERIFIED
AT-TFTP Server 1.8 - 'Read' Request Remote Denial of Service
by Antu Sanadi
EIP-2026-109131 EXPLOITDB python VERIFIED
LightNEasy 3.2.3 - 'userhandle' Cookie SQL Injection
by AutoSec Tools
CVE-2011-1591 EXPLOITDB python VERIFIED
Wireshark <1.4.5 - Buffer Overflow
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allows remote attackers to execute arbitrary code via a crafted .pcap file.
by sickness
EIP-2026-117775 EXPLOITDB python VERIFIED
PlaylistMaker 1.5 - '.txt' Local Buffer Overflow
by C4SS!0 G0M3S
EIP-2026-112702 EXPLOITDB python
TinyBB 1.4 - Blind SQL Injection / Full Path Disclosure
by swami
EIP-2026-103680 EXPLOITDB python VERIFIED
TOTVS ERP Microsiga Protheus 8/10 - Memory Corruption (Denial of Service)
by waKKu
CVE-2011-0364 EXPLOITDB python VERIFIED
Cisco Security Agent - Code Injection
The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers to create arbitrary files and execute arbitrary code via unspecified parameters in a crafted st_upload request.
by Gerry Eisenhaur
EIP-2026-118164 EXPLOITDB python VERIFIED
Wordtrainer 3.0 - '.ord' Local Buffer Overflow
by C4SS!0 G0M3S
EIP-2026-115464 EXPLOITDB python VERIFIED
IrfanView 4.28 - '.ICO' Without Transparent Colour Denial of Service / Remote Denial of Service
by BraniX
EIP-2026-115463 EXPLOITDB python VERIFIED
IrfanView 4.28 - '.ICO' With Transparent Colour Denial of Service / Remote Denial of Service
by BraniX
EIP-2026-108584 EXPLOITDB python VERIFIED
Joomla! Component com_virtuemart 1.1.7 - Blind SQL Injection
by TecR0c & mr_me