dos
dos 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
XnView 2.03 – ‘.pct’ Buffer Overflow
Core Security - Corelabs Advisory
Artweaver 3.1.5 – ‘.awd’ Buffer Overflow
Core Security - Corelabs Advisory
Samsung PS50C7700 TV – Denial of Service
#!/usr/bin/python
VbsEdit 5.9.3 – ‘.smi’ Buffer Overflow (PoC)
# Exploit Title: VbsEdit 5.9.3(.smi file handling) Buffer overflow vulnerability
Microsoft Windows Movie Maker 2.1.4026.0 – ‘.wav’ Crash (PoC)
# Exploit Title: Windows Movie Maker Version 2.1.4026.0 (.wav) - Crash POC
Light Audio Mixer 1.0.12 – ‘.wav’ Crash (PoC)
# Exploit Title: Light Audio Mixer Version 1.0.12 (.wav) - Crash POC
Kate’s Video Toolkit 7.0 – ‘.wav’ Crash (PoC)
# Exploit Title: Kate's Video Toolkit Version 7.0 (.wav) - Crash POC
rpcbind – CALLIT procedure UDP Crash (PoC)
#!/usr/bin/ruby
Squid 3.3.5 – Denial of Service (PoC)
#Squid Crash PoC
Tri-PLC Nano-10 r81 – Denial of Service
# Exploit Title: Tri-PLC Nano-10 DoS
Jolix Media Player 1.1.0 – ‘.m3u’ Denial of Service
#!/usr/bin/python
Apache CXF < 2.5.10/2.6.7/2.7.4 - Denial of Service
SEC Consult Vulnerability Lab Security Advisory < 20130709-0 >
Realtek Sound Manager AvRack – ‘.wav’ Crash (PoC)
# !/usr/bin/python
RealNetworks RealPlayer – Denial of Service
source: https://www.securityfocus.com/bid/60903/info
Winamp 5.63 – Stack Buffer Overflow
Inshell Security Advisory
Winamp 5.63 – Invalid Pointer Dereference
Inshell Security Advisory
Opera 12.15 – vtable Corruption
Opera 12.15 DOS POC
FileCOPA FTP Server – Remote Denial of Service
source: https://www.securityfocus.com/bid/60909/info
libvirt – ‘virConnectListAllInterfaces’ Method Denial of Service
source: https://www.securityfocus.com/bid/60876/info
VideoLAN VLC Media Player 2.0.7 – ‘.png’ Crash (PoC)
#!/usr/bin/python
AVS Media Player 4.1.11.100 – ‘.ac3’ Denial of Service
#!/usr/bin/python
Microsoft PowerPoint 2007 – Crash (PoC)
# Title : Microsoft Office PowerPoint 2007 Crash PoC
Oracle VM VirtualBox 4.0 – ‘tracepath’ Local Denial of Service
source: https://www.securityfocus.com/bid/60794/info
Baby FTP Server 1.24 – Denial of Service (1)
#!/usr/bin/perl
PEiD 0.95 – Memory Corruption (PoC)
# Title: PEiD v0.95 Memory Corruption
MusicBee 2.0.4663 – ‘.m3u’ Denial of Service
#!/usr/bin/perl
Easy LAN Folder Share 3.2.0.100 – Buffer Overflow
# Exploit Title: Easy LAN Folder Share Version 3.2.0.100 Buffer Overflow vulnerability(SEH)
AXIS Media Control 6.2.10.11 – Unsafe ActiveX Method
========================================================================
Ubiquiti airCam RTSP Service 1.1.5 – Buffer Overflow (PoC)
Core Security - Corelabs Advisory
Syslog Server 1.2.3 – Crash (PoC)
#!/usr/bin/python
Sami FTP Server 2.0.1 – RETR Denial of Service
#!/usr/bin/python
WinRadius 2.11 – Denial of Service
#!/usr/bin/python
Cisco ASA < 8.4.4.6 < 8.2.5.32 - Ethernet Information Leak
#!/usr/bin/env python
Quick TFTP Server Pro 2.2 – Denial of Service
#!/usr/bin/python
Linux Kernel 3.0.5 – ‘test_root()’ Local Denial of Service
source: https://www.securityfocus.com/bid/60586/info
Apple Mac OSX Server – DirectoryService Buffer Overflow
Core Security - Corelabs Advisory
PEStudio 3.69 – Denial of Service
# Title: PEStudio Version 3.69 Denial of Service
ModSecurity – Remote Null Pointer Dereference
Source: http://packetstormsecurity.com/files/121815/modsecurity_cve_2013_2765_check.py.txt
Code::Blocks – Denial of Service
source: https://www.securityfocus.com/bid/60208/info
CodeBlocks 12.11 (OSX) – Crash (PoC)
# Exploit Title: CodeBlocks 12.11 (Mac OS X) Crash POC
SAS Integration Technologies Client 9.31_M1 ‘SASspk.dll’ – Stack Overflow
SAS Integration Technologies Client ActiveX Stack BoF 0-day
SIEMENS Solid Edge ST4/ST5 SEListCtrlX – ActiveX SetItemReadOnly Arbitrary Memory Rewrite Remote Code Execution
SIEMENS Solid Edge ST4/ST5 SEListCtrlX ActiveX Control SetItemReadOnly
Microsoft Windows – Win32k!EPATHOBJ::pprFlattenRec Uninitialized Next Pointer Testcase
I'm quite proud of this list cycle trick, here's how to turn it into an
Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)
# Exploit Title: nginx v1.3.9-1.4.0 DOS POC (CVE-2013-2028)
Serva 32 TFTP 2.1.0 – Buffer Overflow (Denial of Service) (PoC)
#Serva 32 TFTP Buffer overflow DoS
Quick Search 1.1.0.189 – Buffer Overflow (SEH)
# Exploit Title: Quick Search Version 1.1.0.189 Buffer Overflow vulnerability(SEH)
MiniWeb HTTP Server 300 – Crash (PoC)
# MiniWeb HTTP server (build 300, built on Feb 28 2013) by Stanley Huang