Exploitdb Exploits

31,394 exploits tracked across all sources.

Sort: Activity Stars
EIP-2026-115003 EXPLOITDB text VERIFIED
Boloto Media Player 1.0.0.9 - '.pls' File Denial of Service
by Dr_IDE
CVE-2009-3625 EXPLOITDB text VERIFIED
Sahana 0.6.2.2 - Path Traversal via Mod Parameter
Directory traversal vulnerability in www/index.php in Sahana 0.6.2.2 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter.
by Greg Miernicki
CVE-2009-2267 EXPLOITDB text VERIFIED
VMware ESX <4.0 - Privilege Escalation
VMware Workstation 6.5.x before 6.5.3 build 185404, VMware Player 2.5.x before 2.5.3 build 185404, VMware ACE 2.5.x before 2.5.3 build 185404, VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138, VMware Fusion 2.x before 2.0.6 build 196839, VMware ESXi 3.5 and 4.0, and VMware ESX 2.5.5, 3.0.3, 3.5, and 4.0, when Virtual-8086 mode is used, do not properly set the exception code upon a page fault (aka #PF) exception, which allows guest OS users to gain privileges on the guest OS by specifying a crafted value for the cs register.
by Tavis Ormandy & Julien Tinnes
CVE-2009-3373 EXPLOITDB text VERIFIED
Firefox < 3.0.15 and 3.5.x < 3.5.4 - Remote Code Execution via GIF Image Parser
Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.
by regenrecht
EIP-2026-103150 EXPLOITDB text VERIFIED
KDE 4.3.2 - Multiple Input Validation Vulnerabilities
by Tim Brown
CVE-2009-0689 EXPLOITDB text VERIFIED
K-Meleon 1.5.3 - Heap-Based Buffer Overflow via Large Precision Value in printf Format Argument
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.
by Alin Rad Pop
EIP-2026-118968 EXPLOITDB text VERIFIED
Novell eDirectory 8.8sp5 - Remote Buffer Overflow
by karak0rsan_ murderkey
CVE-2009-4587 EXPLOITDB text VERIFIED
Cherokee Web Server 0.5.4 - DoS
Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word.
by Usman Saeed
CVE-2009-3833 EXPLOITDB text VERIFIED
TFTgallery 0.13 - Cross-Site Scripting via Album Parameter
Cross-site scripting (XSS) vulnerability in index.php in TFTgallery 0.13 allows remote attackers to inject arbitrary web script or HTML via the album parameter.
by blake
EIP-2026-111837 EXPLOITDB text VERIFIED
RunCMS 2ma - 'post.php' SQL Injection
by bookoo
CVE-2009-3804 EXPLOITDB text VERIFIED
RunCMS 2M1 - Authenticated SQL Injection via Forum Post Parameters
Multiple SQL injection vulnerabilities in modules/forum/post.php in RunCMS 2M1 allow remote authenticated users to execute arbitrary SQL commands via (1) the pid parameter, which is not properly handled by the store function in modules/forum/class/class.forumposts.php, or (2) the topic_id parameter.
by bookoo
CVE-2009-4610 EXPLOITDB text VERIFIED
Mort Bay Jetty 6.x and 7.0.0 - Cross-Site Scripting via JSP Dump Query String or Session Dump Parameters
Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature, or the (2) Name or (3) Value parameter to the default URI for the Session Dump Servlet under session/.
by Antonion Parata
CVE-2009-3830 EXPLOITDB text VERIFIED
Microsoft Office SharePoint Server 2007 Unauthenticated ASP.NET Source Code Disclosure
The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
by Daniel Martin
CVE-2009-4612 EXPLOITDB text VERIFIED
Mort Bay Jetty 6.1.x-6.1.21 - Cross-Site Scripting via PATH_INFO to Snoop Page
Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3) jspsnoop/IOException/, and possibly the PATH_INFO to (4) snoop.jsp.
by aScii
CVE-2009-3838 EXPLOITDB text VERIFIED
Pegasus Mail 4.41 - Stack-based Buffer Overflow via Long POP3 Error Message
Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message.
by Francis Provencher
CVE-2009-3577 EXPLOITDB text VERIFIED
Autodesk 3ds Max 6-9 and 2008-2010 - Remote Code Execution via MAXScript DOSCommand Method
Autodesk 3D Studio Max (3DSMax) 6 through 9 and 2008 through 2010 allows remote attackers to execute arbitrary code via a .max file with a MAXScript statement that calls the DOSCommand method, related to "application callbacks."
by Sebastian Tello
EIP-2026-117252 EXPLOITDB text VERIFIED
GPG4Win GNU - Privacy Assistant
by Dr_IDE
CVE-2009-3837 EXPLOITDB text VERIFIED
Eureka Email 2.2q - Remote Code Execution via Long POP3 Error Message
Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error message.
by Francis Provencher
EIP-2026-112824 EXPLOITDB text VERIFIED
TwonkyMedia Server 4.4.17/5.0.65 - Cross-Site Scripting
by Davide Canali
CVE-2009-4535 EXPLOITDB text VERIFIED
Mongoose < 2.8.0 - Unauthenticated Source Code Exposure via URI Trailing Slash
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.
by Dr_IDE
EIP-2026-108829 EXPLOITDB text VERIFIED
Joomla! Component Photo Blog alpha 3 < alpha 3a - SQL Injection
by kaMtiEz
CVE-2009-3835 EXPLOITDB text VERIFIED
JShop - SQL Injection via pid Parameter
SQL injection vulnerability in the JShop (com_jshop) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the pid parameter in a product action to index.php.
by Don Tukulesto
CVE-2009-3641 EXPLOITDB text VERIFIED
Snort < 2.8.5.1 - Denial of Service via Crafted IPv6 Packet
Snort before 2.8.5.1, when the -v option is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted IPv6 packet that uses the (1) TCP or (2) ICMP protocol.
by laurent gaffie
EIP-2026-102956 EXPLOITDB text VERIFIED
proc File - Descriptors Directory Permissions Bypass
by Pavel Machek
EIP-2026-102703 EXPLOITDB text VERIFIED
Nginx 0.7.0 < 0.7.61 / 0.6.0 < 0.6.38 / 0.5.0 < 0.5.37 / 0.4.0 < 0.4.14 - Denial of Service (PoC)
by Zeus Penguin