header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Paintshop Pro X7 GIF Conversion Heap Memory Corruption Vulnerabilities (LZWMinimumCodeSize)

The vulnerability is caused due to a boundary error within the processing of GIF images and can be exploited to cause a heap-based memory corruption. Successful exploitation may allow execution of arbitrary code.

Crash PoC Seagate Dashboard 4.0.21.0

The dasboard tool is part of the Seagate software solution for storage. The Dashboard.exe process opens a random port in the 5000-6000 range on each launch. The attached Python script will send 3100 A's to the target port. This will cause a crash in the Dashboard.exe process.

Owning the Internet Printing: A Case Study in Exploit Mitigations

When parsing a print job request, cupsd can be forced to over-decrement the reference count for a string from the request. As a result, an attacker can prematurely ffree a string, and use the freed memory to control the execution flow of cupsd.

HansoPlayer 3.4.0 Memory Corruption PoC

HansoPlayer 3.4.0 is vulnerable to a memory corruption vulnerability due to improper validation of user-supplied input. An attacker can exploit this vulnerability by crafting a malicious .wav file and sending it to the victim, resulting in a denial of service condition.

ManageEngine SupportCenter Plus 7.90 – Multiple Vulnerabilities

Multiple vulnerabilities have been discovered in the official ManageEngine SupportCenter Plus v7.90 web-application. The vulnerabilities are located in the `/helpdesk/` directory and the `/helpdesk/Admin/` directory. Remote attackers are able to inject malicious script codes to the application-side of the vulnerable service. The vulnerabilities are located in the `name` and `description` value of the `/helpdesk/Admin/EditCategory.jsp` and `/helpdesk/Admin/EditPriority.jsp` POST method request. Remote attackers are able to inject malicious script codes to the application-side of the vulnerable service.

BlackCat CMS v1.1.1 Arbitrary File Download Vulnerability

BlackCat CMS v1.1.1 is vulnerable to an arbitrary file download vulnerability due to insufficient sanitization of user input. An attacker can exploit this vulnerability by sending a crafted HTTP request to the vulnerable server, which will allow the attacker to download any file from the server.

Recent Exploits: