Kontakt Player 4 suffers from a buffer overflow vulnerability when parsing ".nki" files. The application fails in boundary checking of the user input resulting in a crash. The attacker can leverage from this scenario to execute arbitrary code on the affected system. Failed attempts will result in denial of service.
Adobe Shockwave Player version 11.5.6.606 and earlier suffers from memory consumption/corruption and buffer overflow vulnerabilities that can lead to denial of service and arbitrary code execution. The vulnerabilities occur when processing .dir files, causing a crash and memory register overwrite.
The application suffers from multiple stored XSS vulnerabilities. Input thru several parameters is not sanitized allowing the attacker to execute HTML code into user's browser session on the affected site. Also, couple of HTTP header elements are vulnerable to XSS.
A specially crafted m3u file with 800000 A characters can cause an integer division by zero vulnerability in Zortam MP3 Player 1.50, leading to a denial of service.
Retina WiFi Scanner is a tool to be used to detect IEEE 802.11 (WiFi) based devices. A buffer overflow vulnerability exists in Retina WiFi Scanner 1.0.8.68 when parsing .rws files. An attacker can exploit this vulnerability by supplying a specially crafted .rws file, which can lead to arbitrary code execution.
Carom 3D is an online multi-user billiard game created with special 3D graphic effects. The world famous korean game Carom3D suffers from a buffer overflow and a denial of service vulnerability. The BoF is triggered at runtime when we append 218 > bytes as an argument. ~1000 bytes overwrites SEH. The denial of service is triggered when a user creates a LAN Game (cred. needed), creates a room and awaits other players to join the game. While awaiting (listening on port 28012), with a simple HTTP GET/POST, an attacker can lockdown the GUI of the user created the room, not alowing to start or even exit the game's GUI, unless forced quit (X).
AIMP version 2.51 build 330 suffers from a stack based buffer overflow vulnerability that can be exploited via malicious media file that supports ID3 tags (mp3). EIP and ECX registers gets overwritten, including the SE handler and the pointer to the next SEH record. The issue is trigered by playing the file (crashes within 5 seconds) or by viewing the file's metadata or by pressing the F4 key and selecting the ID3v1 or ID3v2 tab.
This exploit is for ViPlay3 version 3.00 or lower. It is a local stack overflow vulnerability that can be exploited by creating a malicious .vpl file. The malicious file contains a large number of 'A' characters which causes a stack overflow when the file is opened. This can lead to arbitrary code execution.
This exploit sends a crafted packet of a certain length to the remote FTP server, appending it to the USER command and requesting the remote FTP server denies requests for other legitimate users.
MantisBT is a free popular web-based bugtracking system. It is written in the PHP scripting language and works with MySQL, MS SQL, and PostgreSQL databases and a webserver. MantisBT has been installed on Windows, Linux, Mac OS, OS/2, and others. Almost any web browser should be able to function as a client. It is released under the terms of the GNU General Public License (GPL). Mantis Bug Tracker suffers from a cross-site scripting and a path disclosure vulnerability. The XSS issue is triggered when input passed via the 'db_type' parameter to the admin/upgrade_unattended.php script is not properly sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site. The PD weakness is caused due to the application displaying the full installation path in an error report, when supplying an invalid 'db_type' parameter to the admin/upgrade_unattended.php script.