Exploitdb Exploits

2,689 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-113491 EXPLOITDB ruby VERIFIED
WordPress Core 1.5.1.1 < 2.2.2 - Multiple Vulnerabilities
by Lance M. Havok
CVE-2004-2685 EXPLOITDB ruby VERIFIED
YoungZSoft CCProxy < 6.2 - Remote Code Execution via Long Ping Command
Buffer overflow in YoungZSoft CCProxy 6.2 and earlier allows remote attackers to execute arbitrary code via a long address in a ping (p) command to the Telnet proxy service, a different vector than CVE-2004-2416.
by Patrick Webster
CVE-2007-4584 EXPLOITDB ruby VERIFIED
BitchX 1.1 Final - Remote Code Execution via MODE Command Buffer Overflow
Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in a MODE command, related to the p_mode variable.
by bannedit
CVE-2007-4560 EXPLOITDB ruby VERIFIED
ClamAV < 0.91.2 - Remote Code Execution via Shell Metacharacters in Sendmail Recipient Field
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary commands via shell metacharacters that are used in a certain popen call, involving the "recipient field of sendmail."
by patrick
CVE-2007-3763 EXPLOITDB ruby VERIFIED
Asterisk < 1.2.22 and 1.4.x < 1.4.8 - Denial of Service via Crafted IAX2 LAGRQ or LAGRP Frame
The IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1, AsteriskNOW before beta7, Appliance Developer Kit before 0.5.0, and s800i before 1.0.2 allows remote attackers to cause a denial of service (crash) via a crafted (1) LAGRQ or (2) LAGRP frame that contains information elements of IAX frames, which results in a NULL pointer dereference when Asterisk does not properly set an associated variable.
by tenkei_ev
CVE-2007-0016 EXPLOITDB ruby VERIFIED
MoviePlay 4.76 - Stack-Based Buffer Overflow via LST File Filename
Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a LST file.
by n00b
CVE-2007-3098 EXPLOITDB ruby VERIFIED
SNMPc < 7.0.18 - Denial of Service via Crafted Packet to Port 165/TCP
The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a denial of service (crash) via a crafted packet to port 165/TCP.
by En Douli
CVE-2007-3068 EXPLOITDB ruby VERIFIED
DVD X Player 4.1 Professional - Stack-Based Buffer Overflow via PLF Playlist Filename
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF playlist containing a long filename.
by n00b
CVE-2007-2761 EXPLOITDB ruby VERIFIED
MagicISO <5.4.239 - Buffer Overflow
Stack-based buffer overflow in MagicISO 5.4 build 239 and earlier allows remote attackers to execute arbitrary code via a long filename in a .cue file.
by n00b
CVE-2007-2446 EXPLOITDB ruby VERIFIED
Samba 3.0.0-3.0.25rc3 - Buffer Overflow
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers to execute arbitrary code via crafted MS-RPC requests involving (1) DFSEnum (netdfs_io_dfs_EnumInfo_d), (2) RFNPCNEX (smb_io_notify_option_type_data), (3) LsarAddPrivilegesToAccount (lsa_io_privilege_set), (4) NetSetFileSecurity (sec_io_acl), or (5) LsarLookupSids/LsarLookupSids2 (lsa_io_trans_names).
by Adriano Lima
CVE-2007-2508 EXPLOITDB ruby VERIFIED
Trend Micro ServerProtect <5.58 - Buffer Overflow
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary code via crafted data to (1) TCP port 5168, which triggers an overflow in the CAgRpcClient::CreateBinding function in the AgRpcCln.dll library in SpntSvc.exe; or (2) TCP port 3628, which triggers an overflow in EarthAgent.exe. NOTE: both issues are reachable via TmRpcSrv.dll.
by MC
CVE-2007-2175 EXPLOITDB ruby VERIFIED
Apple QuickTime Java extensions - RCE
Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows remote attackers to execute arbitrary code via parameters to the toQTPointer method in quicktime.util.QTHandleRef, which can be used to modify arbitrary memory when creating QTPointerRef objects, as demonstrated during the "PWN 2 0WN" contest at CanSecWest 2007.
by H D Moore
CVE-2007-3947 EXPLOITDB ruby VERIFIED
lighttpd < 1.4.15 - Denial of Service via Duplicate HTTP Headers
request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault.
by Abhisek Datta
CVE-2007-1674 EXPLOITDB ruby VERIFIED
LANDesk Management Suite 8.7 - Remote Code Execution via Crafted UDP Packet to Alert Service
Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitrary code via a crafted packet to port 65535/UDP.
by Aaron Portnoy
EIP-2026-118543 EXPLOITDB ruby VERIFIED
FileCOPA FTP Server 1.01 - 'LIST' Remote Buffer Overflow (2)
by Umesh Wanve
CVE-2006-5820 EXPLOITDB ruby VERIFIED
AOL 9.0 Security Edition - Remote Code Execution via SuperBuddy ActiveX Control
The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition dereferences an arbitrary function pointer, which allows remote attackers to execute arbitrary code via a modified pointer value.
by Krad Chad
CVE-2007-1435 EXPLOITDB ruby VERIFIED
D-Link TFTP Server 1.0 - Denial of Service via Long GET or PUT Request
Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request, which triggers memory corruption. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
by LSO
EIP-2026-104017 EXPLOITDB ruby VERIFIED
Opera 9.10 - Configuration Overwrite (Metasploit)
by egypt
CVE-2007-1286 EXPLOITDB ruby VERIFIED
PHP < 4.4.4 - Remote Code Execution via Long String to unserialize Function
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long string to the unserialize function, which triggers the overflow in the ZVAL reference counter.
by sesser
CVE-2007-0882 EXPLOITDB ruby VERIFIED
Solaris 10 and 11 - Unauthenticated Argument Injection in telnetd via -f Sequence
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterprets certain client "-f" sequences as valid requests for the login program to skip authentication, which allows remote attackers to log into certain accounts, as demonstrated by the bin account.
by MC
CVE-2007-0816 EXPLOITDB ruby VERIFIED
CA BrightStor ARCserve Backup <11.5 SP2 - DoS
The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlier allows remote attackers to cause a denial of service (service crash) via a crafted TADDR2UADDR that triggers a null pointer dereference in catirpc.dll, possibly related to null credentials or verifier fields.
by Shirkdog
CVE-2007-0710 EXPLOITDB ruby VERIFIED
iChat - Denial of Service via Bonjour Functionality
The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.
by MoAB
CVE-2007-0467 EXPLOITDB ruby VERIFIED
Apple Mac OS X 10.4.8 - Privilege Escalation
crashdump in Apple Mac OS X 10.4.8 allows local users in the admin group to modify arbitrary files or gain privileges via a symlink attack on application logs in /Library/Logs/CrashReporter/.
by MoAB
CVE-2007-0464 EXPLOITDB ruby VERIFIED
CFNetwork 129.19 - Denial of Service via Crafted HTTP 301 Response
The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application crash) via a crafted HTTP 301 response, which results in a NULL pointer dereference.
by MoAB
CVE-2007-0023 EXPLOITDB ruby VERIFIED
Apple Mac OS X 10.4.8 - Privilege Escalation
The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combination with diskutil, allows local users to gain privileges via a malicious InputManager in Library/InputManagers in a user's home directory, which is executed when Cocoa applications attempt to notify the user.
by MoAB