Exploits

Exploit Database - Exploits for Penetration Testers, Researchers, and Ethical Hackers

共24443Exploits
日期 标题 类型 平台 作者
2016-12-06

Google Android – Inter-Process munmap with User-Controlled Size in android.graphics.Bitmap

  • remote
  • android
  • Google Security Research
    2016-12-06

    Microsoft PowerShell – XML External Entity Injection

  • local
  • windows
  • hyp3rlinx
    2016-12-06

    Linux Kernel 4.4.0 (Ubuntu 14.04/16.04 x86-64) – ‘AF_PACKET’ Race Condition Privilege Escalation

  • local
  • linux_x86-64
  • rebel
    2016-12-05

    Shuttle Tech ADSL Wireless 920 WM – Multiple Vulnerabilities

  • remote
  • hardware
  • Persian Hack Team
    2016-12-05

    NetCat 0.7.1 – Denial of Service

  • dos
  • linux
  • n30m1nd
    2016-12-05

    Apache CouchDB 2.0.0 – Local Privilege Escalation

  • local
  • windows
  • hyp3rlinx
    2016-12-05

    Microsoft MSINFO32.EXE 6.1.7601 – ‘.NFO’ XML External Entity Injection

  • local
  • windows
  • hyp3rlinx
    2016-12-05

    Microsoft Event Viewer 1.0 – XML External Entity Injection

  • local
  • windows
  • hyp3rlinx
    2016-12-05

    WordPress Plugin Single Personal Message 1.0.3 – SQL Injection

  • webapps
  • php
  • Lenon Leite
    2016-12-05

    DiskBoss Enterprise 7.4.28 – ‘GET’ Remote Buffer Overflow

  • remote
  • windows
  • vportal
    2016-12-05

    Dup Scout Enterprise 9.1.14 – Remote Buffer Overflow (SEH)

  • remote
  • windows
  • vportal
    2016-12-04

    Alcatel Lucent Omnivista 8770 – Remote Code Execution

  • remote
  • windows
  • malerisch
    2016-12-04

    Microsoft Windows Media Center 6.1.7600 – ‘ehshell.exe’ XML External Entity Injection

  • local
  • windows
  • hyp3rlinx
    2016-12-04

    Microsoft Excel Starter 2010 – XML External Entity Injection

  • local
  • windows
  • hyp3rlinx
    2016-12-04

    Microsoft Authorization Manager 6.1.7601 – ‘azman’ XML External Entity Injection

  • local
  • windows
  • hyp3rlinx
    2016-12-04

    BlackStratus LOGStorm 4.5.1.35/4.5.1.96 – Remote Code Execution

  • remote
  • hardware
  • Jeremy Brown
    2016-12-03

    Smart Guard Network Manager 6.3.2 – SQL Injection

  • webapps
  • php
  • Rahul Raz
    2016-12-02

    Xfinity Gateway – Remote Code Execution

  • webapps
  • hardware
  • Gregory Smiley
    2016-12-01

    Broadcom BCM43xx Wi-Fi – ‘BroadPWN’ Denial of Service

  • dos
  • android
  • 649
    2016-12-01

    Tor (Firefox 41 < 50) - Code Execution

  • local
  • windows
  • 649
    2016-12-01

    Disk Savvy Enterprise 9.1.14 – ‘GET’ Remote Buffer Overflow

  • remote
  • windows
  • vportal
    2016-11-30

    WordPress Plugin WP Vault 0.8.6.6 – Local File Inclusion

  • webapps
  • php
  • Lenon Leite
    2016-11-30

    Xitami Web Server 5.0a0 – Denial of Service

  • dos
  • windows
  • sm
    2016-11-30

    Xfinity Gateway – Cross-Site Request Forgery

  • webapps
  • hardware
  • Pabstersac
    2016-11-29

    WinPower 4.9.0.4 – Local Privilege Escalation

  • local
  • windows
  • Kacper Szurek
    2016-11-28

    Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 – Multiple Vulnerabilities

  • webapps
  • hardware
  • SlidingWindow
    2016-11-28

    Disk Sorter Enterprise 9.1.12 – ‘Login’ Remote Buffer Overflow

  • remote
  • windows
  • Tulpa
    2016-11-28

    Dup Scout Enterprise 9.1.14 – ‘Login’ Remote Buffer Overflow

  • remote
  • windows
  • Tulpa
    2016-11-28

    Sync Breeze Enterprise 9.1.16 – ‘Login’ Remote Buffer Overflow

  • remote
  • windows
  • Tulpa
    2016-11-28

    VX Search Enterprise 9.1.12 – ‘Login’ Remote Buffer Overflow

  • remote
  • windows
  • Tulpa
    2016-11-28

    Google Android – ‘BadKernel’ Remote Code Execution

  • remote
  • android
  • Guang Gong
    2016-11-28

    Microsoft Internet Explorer 8/9/10/11 – MSHTML ‘DOMImplementation’ Type Confusion (MS16-009)

  • dos
  • windows
  • Skylined
    2016-11-28

    Microsoft Internet Explorer 10 – MSHTML ‘CEdit­Adorner::Detach’ Use-After-Free (MS13-047)

  • dos
  • windows
  • Skylined
    2016-11-28

    Microsoft Internet Explorer 11 – MSHTML ‘CGenerated­Content::Has­Generated­SVGMarker’ Type Confusion

  • dos
  • windows
  • Skylined
    2016-11-28

    Red Hat JBoss EAP – Deserialization of Untrusted Data

  • webapps
  • java
  • Mediaservice.net Srl.
    2016-11-28

    Microsoft Internet Explorer 8 – MSHTML ‘SRun­Pointer::Span­Qualifier/Run­Type’ Out-Of-Bounds Read (MS15-009)

  • dos
  • windows
  • Skylined
    2016-11-28

    NTP 4.2.8p3 – Denial of Service

  • dos
  • linux
  • Magnus Klaaborg Stubman
    2016-11-28

    Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' 'PTRACE_POKEDATA' Race Condition Privilege Escalation (/etc/passwd Method)

  • local
  • linux
  • FireFart
    2016-11-28

    Tenda/Dlink/Tplink TD-W8961ND – ‘DHCP’ Cross-Site Scripting

  • webapps
  • hardware
  • Vulnerability-Lab
    2016-11-28

    Disk Pulse Enterprise 9.1.16 – ‘Login’ Remote Buffer Overflow

  • remote
  • windows
  • Tulpa
    2016-11-28

    Disk Savvy Enterprise 9.1.14 – ‘Login’ Remote Buffer Overflow

  • remote
  • windows
  • Tulpa
    2016-11-27

    Linux Kernel 2.6.22 < 3.9 - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (/etc/passwd Method)

  • local
  • linux
  • Gabriele Bonacini
    2016-11-27

    Core FTP LE 2.2 – ‘SSH/SFTP’ Remote Buffer Overflow (PoC)

  • dos
  • windows
  • hyp3rlinx
    2016-11-24

    osTicket 1.9.14 – ‘X-Forwarded-For’ Cross-Site Scripting

  • webapps
  • php
  • Joaquin Ramirez Martinez
    2016-11-24

    Remote Utilities Host 6.3 – Denial of Service

  • dos
  • windows
  • Peter Baris
    2016-11-24

    GNU Wget < 1.18 - Access List Bypass / Race Condition

  • remote
  • multiple
  • Dawid Golunski
    2016-11-24

    Microsoft Windows Kernel – ‘win32k.sys NtSetWindowLongPtr’ Local Privilege Escalation (MS16-135) (1)

  • local
  • windows
  • IOactive
    2016-11-23

    UCanCode – Multiple Vulnerabilities

  • dos
  • windows
  • shinnai
    2016-11-23

    Linux Kernel 2.6.32-642/3.16.0-4 – ‘inode’ Integer Overflow

  • dos
  • linux
  • Todor Donev
    2016-11-22

    EasyPHP Devserver 16.1.1 – Cross-Site Request Forgery / Remote Command Execution

  • webapps
  • php
  • hyp3rlinx