Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the wp-pagenavi domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /home/u918112125/domains/exploit.company/public_html/wp-includes/functions.php on line 6114
Exploits 414 - exploit.company
header-logo
Suggest Exploit
explore-vulnerabilities

Explore Vulnerabilities

Version
Year

Explore all Exploits:

Buffer-Overflow Vulnerability in RichFX Basic Player ActiveX Control

The RichFX Basic Player ActiveX Control is prone to a buffer-overflow vulnerability due to inadequate boundary checks on user-supplied data. Successful exploitation of this vulnerability allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control, typically Internet Explorer. Failed exploit attempts may result in denial-of-service conditions.

Cross-site Scripting Vulnerability in VBTube

The VBTube application is prone to a cross-site scripting vulnerability due to insufficient sanitization of user-supplied data. An attacker can exploit this vulnerability to execute arbitrary HTML or script code in a user's browser session, potentially leading to the theft of cookie-based authentication credentials and the ability to launch further attacks.

VMware Tools Privilege Escalation Vulnerability

The VMware Tools application fails to properly drop privileges before performing certain functions, allowing an attacker to exploit this vulnerability in the guest operating system to elevate privileges in the host operating system.

Bandersnatch Multiple Cross-Site Scripting Vulnerabilities

Bandersnatch is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.

Proof of Concept for MOAB-04-01-2007

This is a proof of concept exploit for the MOAB-04-01-2007 vulnerability. It targets iPhoto, a photo management application on macOS. The exploit takes advantage of a buffer overflow vulnerability in iPhoto's handling of XML feeds, allowing an attacker to execute arbitrary code on a target system. By sending a specially crafted XML feed, an attacker can trigger the buffer overflow and gain control over the target system.

Buffer Overflow in MemPlayer

This is a buffer overflow vulnerability in MemPlayer. The vulnerability can be exploited by sending a specially crafted HTTP request to the server, causing a buffer overflow and potentially allowing the attacker to execute arbitrary code on the target system. The vulnerability exists in the MemPlayer version 1.0.3 (Linux).

MySpace Scripts Poll Creator HTML Injection Vulnerability

The MySpace Scripts Poll Creator application is prone to an HTML-injection vulnerability because it fails to properly sanitize user-supplied input before using it in dynamically generated content. This allows an attacker to inject malicious HTML or JavaScript code that can run in the context of the affected site. This can potentially lead to the theft of cookie-based authentication credentials and allow the attacker to control how the site is rendered to the user. Other attacks are also possible.

Aurigma Image Uploader ActiveX Control Multiple Stack-based Buffer Overflow Vulnerabilities

The Aurigma Image Uploader ActiveX control is prone to multiple stack-based buffer-overflow vulnerabilities because it fails to perform adequate boundary checks on user-supplied data. Successfully exploiting these issues allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.

Recent Exploits: