Exploitdb Exploits

4,733 exploits tracked across all sources.

Sort: Activity Stars
CVE-2010-3000 EXPLOITDB python VERIFIED
RealNetworks RealPlayer <11.1 - RCE
Multiple integer overflows in the ParseKnownType function in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1.4 on Windows allow remote attackers to execute arbitrary code via crafted (1) HX_FLV_META_AMF_TYPE_MIXEDARRAY or (2) HX_FLV_META_AMF_TYPE_ARRAY data in an FLV file.
by Abysssec
CVE-2010-3396 EXPLOITDB python VERIFIED
Kingsoft Antivirus <2010.04.26.648 - Buffer Overflow
Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argument to IOCTL 0x80030004. NOTE: some of these details are obtained from third party information.
by Lufeng Li
CVE-2010-2201 EXPLOITDB python VERIFIED
Adobe Acrobat - Resource Management Error
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbitrary code via a PDF file with crafted Flash content involving the (1) pushstring (0x2C) operator, (2) debugfile (0xF1) operator, and an "invalid pointer vulnerability" that triggers memory corruption, a different vulnerability than CVE-2010-1285 and CVE-2010-2168.
by Abysssec
CVE-2010-1900 EXPLOITDB python VERIFIED
Microsoft Works - Code Injection
Microsoft Office Word 2002 SP3, 2003 SP3, and 2007 SP2; Microsoft Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Word Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Works 9 do not properly handle malformed records in a Word file, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, aka "Word Record Parsing Vulnerability."
by Abysssec
CVE-2010-1247 EXPLOITDB python VERIFIED
Microsoft Office Excel 2002 SP3 - RCE
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 allows remote attackers to execute arbitrary code via an Excel file with a malformed RTD (0x813) record that triggers heap corruption, aka "Excel Memory Corruption Vulnerability," a different vulnerability than CVE-2010-0823 and CVE-2010-1249.
by Abysssec
EIP-2026-119520 EXPLOITDB python VERIFIED
Audiotran 1.4.2.4 - Local Overflow (SEH)
by Abhishek Lyall
EIP-2026-116713 EXPLOITDB python VERIFIED
Acoustica MP3 Audio Mixer 2.471 - Extended .M3U Directives (SEH)
by Carlos Mario Penagos Hollmann
CVE-2010-1199 EXPLOITDB python VERIFIED
Mozilla Firefox < 2.0.4 - Numeric Error
Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.
by Abysssec
CVE-2010-1681 EXPLOITDB python VERIFIED
Microsoft Visio - Memory Corruption
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to execute arbitrary code via a crafted DXF file, a different vulnerability than CVE-2010-0254 and CVE-2010-0256.
by Abysssec
CVE-2010-4913 EXPLOITDB python VERIFIED
ColdGen ColdUserGroup 1.06 - XSS
Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. NOTE: some of these details are obtained from third party information.
by mr_me
CVE-2010-4916 EXPLOITDB python VERIFIED
ColdGen ColdUserGroup 1.06 - SQL Injection
Multiple SQL injection vulnerabilities in index.cfm in ColdGen ColdUserGroup 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) ArticleID or (2) LibraryID parameter.
by mr_me
CVE-2010-4910 EXPLOITDB python VERIFIED
ColdGen ColdCalendar <2.06 - SQL Injection
SQL injection vulnerability in index.cfm in ColdGen ColdCalendar 2.06 allows remote attackers to execute arbitrary SQL commands via the EventID parameter in a ViewEventDetails action.
by mr_me
EIP-2026-116120 EXPLOITDB python VERIFIED
QQPlayer 2.3.696.400p1 - '.wav' Denial of Service
by s-dz
EIP-2026-104528 EXPLOITDB python VERIFIED
Novell Netware - NWFTPD RMD/RNFR/DELE Argument Parsing Buffer Overflow
by Abysssec
CVE-2010-2703 EXPLOITDB python VERIFIED
HP OpenView Network Node Manager <7.53 - Buffer Overflow
Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53, when running on Windows, allows remote attackers to execute arbitrary code via a long HTTP request to webappmon.exe.
by Abysssec
EIP-2026-114860 EXPLOITDB python VERIFIED
Adobe Acrobat and Reader 9.3.4 - 'acroform_PlugInMain' Memory Corruption
by ITSecTeam
CVE-2010-0480 EXPLOITDB python VERIFIED
Microsoft Windows 2000 - Memory Corruption
Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to execute arbitrary code via a crafted AVI file, aka "MPEG Layer-3 Audio Decoder Stack Overflow Vulnerability."
by Abysssec
EIP-2026-116494 EXPLOITDB python VERIFIED
Virtual DJ Trial 6.1.2 - Buffer Overflow Crash (SEH) (PoC)
by Abhishek Lyall
CVE-2010-4917 EXPLOITDB python VERIFIED
A-Blog 2.0 - SQL Injection
SQL injection vulnerability in sources/search.php in A-Blog 2.0 allows remote attackers to execute arbitrary SQL commands via the words parameter.
by Ptrace Security
CVE-2010-0265 EXPLOITDB python VERIFIED
Microsoft Windows Movie Maker - Memory Corruption
Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers to execute arbitrary code via a crafted project (.MSWMM) file, aka "Movie Maker and Producer Buffer Overflow Vulnerability."
by Abysssec
EIP-2026-116493 EXPLOITDB python VERIFIED
VideoLAN VLC Media Player < 1.1.4 - '.xspf smb://' URI Handling Remote Stack Overflow (PoC)
by s-dz
EIP-2026-109363 EXPLOITDB python VERIFIED
mBlogger 1.0.04 - 'addcomment.php' Persistent Cross-Site Scripting
by Ptrace Security
CVE-2010-0519 EXPLOITDB python VERIFIED
Apple Mac OS X - Numeric Error
Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a FlashPix image with a malformed SubImage Header Stream containing a NumberOfTiles field with a large value.
by Abysssec
CVE-2010-1297 EXPLOITDB HIGH python VERIFIED
Adobe Flash Player
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, related to authplay.dll and the ActionScript Virtual Machine 2 (AVM2) newfunction instruction, as exploited in the wild in June 2010.
by Abysssec
CVSS 7.8
EIP-2026-106221 EXPLOITDB python VERIFIED
Cpanel PHP - Restriction Bypass
by Abysssec