exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 51 - 75 of 100 RSS Feed

Files

Microsoft XML Core Services Uninitialized Memory
Posted Jul 5, 2012
Authored by Brian Mariani, High-Tech Bridge SA, Frederic Bourla | Site htbridge.com

This is a thorough analysis of the Microsoft XML core services uninitialized memory vulnerability as noted by CVE-2012-1889. It includes proof of concept data to trigger the issue and goes through the flow.

tags | paper, proof of concept
advisories | CVE-2012-1889
SHA-256 | 71478922d4d7dd398af9e4e90d1f859e3494d8ddf266086e502d50612e95667a

Related Files

OpenSSL 0.9.8k Memory Exhaustion
Posted May 19, 2009
Authored by Jon Oberheide

OpenSSL versions 0.9.8k and 1.0.0-beta2 DTLS remote memory exhaustion denial of service exploit.

tags | exploit, remote, denial of service
advisories | CVE-2009-1378
SHA-256 | 707ecaa806e575970e45edb096353e9e70a251a1b313a57024ad97ba671abea1
Linux Kernel 2.6 UDEV Privilege Escalation
Posted May 1, 2009
Authored by Jon Oberheide

Linux 2.6 kernel udev versions below 1.4.1 local privilege escalation exploit.

tags | exploit, kernel, local
systems | linux
advisories | CVE-2009-1185
SHA-256 | bd6992d84b7f36f4d79d12ce8930abcac49295702f6e9938849399ecc5ab82cd
libvirt_proxy 0.5.1 Privilege Escalation
Posted Apr 28, 2009
Authored by Jon Oberheide

libvirt_proxy versions 0.5.1 and below local privilege escalation exploit.

tags | exploit, local
advisories | CVE-2009-0036
SHA-256 | d6a86f33d2c8f6b21caeda9e12fe29f7be896e99bc24a3e50439a596759674f8
Apache Tomcat mod_jk Information Disclosure
Posted Apr 7, 2009
Site tomcat.apache.org

Apache Tomcat mod_jk versions 1.2.0 through 1.2.26 suffer from an information disclosure vulnerability.

tags | advisory, info disclosure
advisories | CVE-2008-5519
SHA-256 | 82a8f73ad304a3a139da882c821b3194c48cbad8270a4c890591b51a66f9f916
pam-krb5 Privilege Escalation
Posted Mar 30, 2009
Authored by Jon Oberheide

pam-krb5 versions below 3.13 local privilege escalation exploit.

tags | exploit, local
advisories | CVE-2009-0360
SHA-256 | ed6caf64e916f13fb22ba283a61616d7a4668b0cdd50588a48572cfcd9deedfb
Apache Tomcat Cross Site Scripting
Posted Mar 6, 2009
Authored by Deniz Cevik | Site tomcat.apache.org

The calendar application for Apache Tomcat contains invalid HTML which renders the cross site scripting protection for the time parameter ineffective. An attacker can therefore perform an cross site scripting attack using the time attribute. Version affected include Tomcat 6.0.0 to 6.0.18, Tomcat 5.5.0 to 5.5.27, and Tomcat 4.1.0 to 4.1.39.

tags | exploit, xss
advisories | CVE-2009-0781
SHA-256 | 2fd4d18e046935391c0b4eb23d19aed3bf6cd14d57e11ae2522468cf694b91a4
Tomcat Information Disclosure
Posted Feb 26, 2009
Authored by Mark Thomas | Site tomcat.apache.org

Apache Tomcat versions 4.1.32 through 4.1.34 and 5.5.10 through 5.5.20 suffer from an information disclosure vulnerability.

tags | advisory, info disclosure
advisories | CVE-2008-4308
SHA-256 | 768d53d9e66098ca1617ffada6c18d5bb474b2b3a0457418984e05a53b42a23e
Linux Kernel SCTP Kernel Memory Disclosure Exploit
Posted Dec 31, 2008
Authored by Jon Oberheide

Linux Kernel versions below 2.6.26.4 SCTP kernel memory disclosure exploit.

tags | exploit, kernel
systems | linux
advisories | CVE-2008-4113
SHA-256 | 7e0bf7e87eb0ba0da140e07ab53740c3709083af939cf0f1e2a5c0226a2ac6db
PHP mbstring Buffer Overflow
Posted Dec 30, 2008
Authored by Moriyoshi Koizumi

PHP versions 5.2.7 and below suffer from a mbstring buffer overflow vulnerability.

tags | advisory, overflow, php
advisories | CVE-2008-5557
SHA-256 | 37409b5b7371a744b1320cc0009af571db7064e7ad18669697f3b62fd7f1c554
Apache Tomcat Information Disclosure
Posted Dec 22, 2008
Authored by Mark Thomas | Site tomcat.apache.org

This vulnerability was originally reported to the Apache Software Foundation as a Tomcat vulnerability. Investigations quickly identified that the root cause was an issue with the UTF-8 charset implementation within the JVM. The issue existed in multiple JVMs including current versions from Sun, HP, IBM, Apple and Apache. It was decided to continue to report this as a Tomcat vulnerability until such time as the JVM vendors had released fixed versions.

tags | advisory, root
systems | apple
advisories | CVE-2008-2938
SHA-256 | e900270f78788247830b00a35c41b325144bc065b616b71c79bd1ef3ec0ed86b
Avahi Remote Denial Of Service Exploit
Posted Dec 22, 2008
Authored by Jon Oberheide

Avahi mDNS daemon versions below 0.6.24 remote denial of service exploit.

tags | exploit, remote, denial of service
advisories | CVE-2008-5081
SHA-256 | 21710acf10701ccd19d56410ec9950524c32406536eccbcb87f1aab4060bb059
Linux Kernel Denial Of Service Exploit
Posted Dec 10, 2008
Authored by Jon Oberheide

Linux kernel versions 2.6.27.8 and below ATMSVC local denial of service exploit.net/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier allows local users to cause a denial of service (kernel infinite loop) by making two calls to svc_listen for the same socket, and then reading a /proc/net/atm/*vc file, related to corruption of the vcc table.

tags | exploit, denial of service, kernel, local
systems | linux
advisories | CVE-2008-5079
SHA-256 | 1ac5511bb7124a05d8d0461db2da89076c5d7276da1e422a0eed18b95223456a
CVE-2008-4000.txt
Posted Oct 20, 2008
Authored by Amichai Shulman | Site imperva.com

PeopleTools version 8.49 suffers from a brute forcing vulnerability that bypasses the account lock-out mechanism.

tags | advisory
advisories | CVE-2008-4000
SHA-256 | 1794832b45dbd92fd22d7dfa4a7894a3017ca74fc0a57e60ed4181884fae20ed
CVE-2008-2625.txt
Posted Oct 20, 2008
Authored by Amichai Shulman | Site imperva.com

Oracle versions 8i, 9i, 10g Release 1, and 10g Release 2 suffer from an unauthenticated proxy vulnerability.

tags | advisory
advisories | CVE-2008-2625
SHA-256 | ec3cad539a775dde2997a1297f85c3d7574fae33267cd0c9794bbc00b97b00db
CVE-2008-3271.txt
Posted Oct 11, 2008
Authored by Mark Thomas | Site tomcat.apache.org

Apache Tomcat versions 4.1.0 to 4.1.31 and 5.5.0 suffer from an information disclosure vulnerability.

tags | advisory, info disclosure
advisories | CVE-2008-3271
SHA-256 | 465aad4edd5d33fc410a93390311c63759bed560f67aa892017afbf7cb22422b
CVE-2008-4042-exploit.c
Posted Sep 16, 2008
Authored by Albert Sellares, Marc Morata Fite | Site wekk.net

Denial of service exploit for Postfix versions 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel.

tags | exploit, denial of service, kernel
systems | linux
advisories | CVE-2008-3889, CVE-2008-4042
SHA-256 | be4de29c579743f90fbea63e452a1da0c2f608677d7e66f78cf782b3ccc6d70c
CVE-2008-3014.pdf
Posted Sep 11, 2008
Site secunia.com

Deep analysis of the integer overflow in Microsoft GDI+ that can occur during the processing of PolyPolygon records in WMF files.

tags | paper, overflow
advisories | CVE-2008-3014
SHA-256 | 7a9b40b846c927ee326e5b2b5de32049d98d127571d293ef63109d59bb828c00
CVE-2008-2938.txt
Posted Sep 10, 2008
Authored by Mark Thomas | Site tomcat.apache.org

Apache Tomcat versions 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 suffer from an information disclosure vulnerability.

tags | advisory, info disclosure
advisories | CVE-2008-2938
SHA-256 | 336ae34f18a11aaa4141e2fcd7aeb318b8b924dd30a3de3cafb02c982c3cd061
CVE-2008-2370.txt
Posted Aug 1, 2008
Authored by Stefano Di Paola | Site tomcat.apache.org

Tomcat versions 4.1.0 to 4.1.37, 5.5.0 to 5.5.26, and 6.0.0 to 6.0.16 all suffer from an information disclosure vulnerability.

tags | advisory, info disclosure
advisories | CVE-2008-2370
SHA-256 | f8c36b93b9442322e44a0b2612396b39102152d21428d8074fa6dbbc58be85ff
CVE-2008-1232.txt
Posted Aug 1, 2008
Authored by Konstantin Kolinko | Site tomcat.apache.org

Tomcat versions 4.1.0 to 4.1.37, 5.5.0 to 5.5.26, and 6.0.0 to 6.0.16 all suffer from a cross site scripting vulnerability in HttpServletResponse.sendError().

tags | advisory, xss
advisories | CVE-2008-1232
SHA-256 | a5cb236b30e41b1e924b392a708b771a95f2290c765c9d8c5a8597f677aa5ddc
CVE-2008-1947.txt
Posted Jun 3, 2008
Authored by Petr Splichal | Site tomcat.apache.org

Tomcat versions 5.5.9 through 5.5.26 and versions 6.0.0 through 6.0.16 suffer from a host-manager cross site scripting vulnerability.

tags | exploit, xss
advisories | CVE-2008-1947
SHA-256 | 8808a3da5ed86e0f31b49d8245c32c84d0730206e950d7964fd18089497a3952
CVE-2008-1387-clamav.txt
Posted Apr 15, 2008
Authored by Hanno Boeck | Site hboeck.de

Clam-AV versions below 0.93 suffer from an endless loop vulnerability when handling specially crafted ARJ files.

tags | advisory
advisories | CVE-2008-1387
SHA-256 | f975acf9d28711c1ba81f2592579ef7b9338976b9b3020f121d957117570ee4d
CVE-2008-0124-s9y.txt
Posted Feb 26, 2008
Authored by Hanno Boeck | Site hboeck.de

Serendipity (S9Y) is vulnerable to cross site scripting vulnerabilities.

tags | advisory, vulnerability, xss
advisories | CVE-2008-0124
SHA-256 | dd63fb188152a551ba836b956d929e9d741646329f28f1ee2f401f93732ec998
CVE-2007-6286.txt
Posted Feb 11, 2008
Site tomcat.apache.org

Apache Tomcat versions 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15 suffer from a duplicate request processing vulnerability.

tags | advisory
advisories | CVE-2007-6286
SHA-256 | 22729b358466fbd68bb4271ffdf26a6060ba0c78b027606cde7fa63482f7d411
CVE-2007-5333.txt
Posted Feb 11, 2008
Site tomcat.apache.org

Apache Tomcat versions 4.1.0 through 4.1.36, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14 suffers from a cookie handling vulnerability that allows for session hi-jacking.

tags | advisory
advisories | CVE-2007-5333
SHA-256 | b39d081913bab5de110b695d04a57477a5c95855e6a8d1817540793912383f76
Page 3 of 4
Back1234Next

File Archive:

June 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    18 Files
  • 2
    Jun 2nd
    12 Files
  • 3
    Jun 3rd
    0 Files
  • 4
    Jun 4th
    0 Files
  • 5
    Jun 5th
    0 Files
  • 6
    Jun 6th
    0 Files
  • 7
    Jun 7th
    0 Files
  • 8
    Jun 8th
    0 Files
  • 9
    Jun 9th
    0 Files
  • 10
    Jun 10th
    0 Files
  • 11
    Jun 11th
    0 Files
  • 12
    Jun 12th
    0 Files
  • 13
    Jun 13th
    0 Files
  • 14
    Jun 14th
    0 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    0 Files
  • 18
    Jun 18th
    0 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close