header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Native Instruments Kontakt 4 Player NKI File Syntactic Analysis Buffer Overflow PoC

Kontakt Player 4 suffers from a buffer overflow vulnerability when parsing ".nki" files. The application fails in boundary checking of the user input resulting in a crash. The attacker can leverage from this scenario to execute arbitrary code on the affected system. Failed attempts will result in denial of service.

Adobe Shockwave Player 11.5.6.606 (DIR) Multiple Memory Vulnerabilities

Adobe Shockwave Player version 11.5.6.606 and earlier suffers from memory consumption/corruption and buffer overflow vulnerabilities that can lead to denial of service and arbitrary code execution. The vulnerabilities occur when processing .dir files, causing a crash and memory register overwrite.

ManageEngine ServiceDesk Plus 8.0 Multiple Stored XSS Vulnerabilities

The application suffers from multiple stored XSS vulnerabilities. Input thru several parameters is not sanitized allowing the attacker to execute HTML code into user's browser session on the affected site. Also, couple of HTTP header elements are vulnerable to XSS.

Retina WiFi Security Scanner 1.0 (.rws parsing) Buffer Overflow Vulnerability

Retina WiFi Scanner is a tool to be used to detect IEEE 802.11 (WiFi) based devices. A buffer overflow vulnerability exists in Retina WiFi Scanner 1.0.8.68 when parsing .rws files. An attacker can exploit this vulnerability by supplying a specially crafted .rws file, which can lead to arbitrary code execution.

Carom3D 5.06 Unicode Buffer Overrun/Denial Of Service Vulnerability

Carom 3D is an online multi-user billiard game created with special 3D graphic effects. The world famous korean game Carom3D suffers from a buffer overflow and a denial of service vulnerability. The BoF is triggered at runtime when we append 218 > bytes as an argument. ~1000 bytes overwrites SEH. The denial of service is triggered when a user creates a LAN Game (cred. needed), creates a room and awaits other players to join the game. While awaiting (listening on port 28012), with a simple HTTP GET/POST, an attacker can lockdown the GUI of the user created the room, not alowing to start or even exit the game's GUI, unless forced quit (X).

AIMP 2.51 build 330 (ID3v1/ID3v2 Tag) Remote Stack Buffer Overflow PoC (SEH)

AIMP version 2.51 build 330 suffers from a stack based buffer overflow vulnerability that can be exploited via malicious media file that supports ID3 tags (mp3). EIP and ECX registers gets overwritten, including the SE handler and the pointer to the next SEH record. The issue is trigered by playing the file (crashes within 5 seconds) or by viewing the file's metadata or by pressing the F4 key and selecting the ID3v1 or ID3v2 tab.

ViPlay3 <= 3.00 (.vpl) Local Stack Overflow PoC

This exploit is for ViPlay3 version 3.00 or lower. It is a local stack overflow vulnerability that can be exploited by creating a malicious .vpl file. The malicious file contains a large number of 'A' characters which causes a stack overflow when the file is opened. This can lead to arbitrary code execution.

MantisBT <=1.2.3 (db_type) Cross-Site Scripting & Path Disclosure Vulnerability

MantisBT is a free popular web-based bugtracking system. It is written in the PHP scripting language and works with MySQL, MS SQL, and PostgreSQL databases and a webserver. MantisBT has been installed on Windows, Linux, Mac OS, OS/2, and others. Almost any web browser should be able to function as a client. It is released under the terms of the GNU General Public License (GPL). Mantis Bug Tracker suffers from a cross-site scripting and a path disclosure vulnerability. The XSS issue is triggered when input passed via the 'db_type' parameter to the admin/upgrade_unattended.php script is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. The PD weakness is caused due to the application displaying the full installation path in an error report, when supplying an invalid 'db_type' parameter to the admin/upgrade_unattended.php script.

Recent Exploits: