Packet Storm new exploits for April, 2009.
5b2bbbbd6b56da1916e90c3fd2a805b8PF in OpenBSD, NetBSD, and various other Unix variants suffer from a null pointer dereference vulnerability.
60d751eefd8b784dbe6d32c93886e27bMercury Audio Player version 1.21 local stack overflow proof of concept exploit that creates a malicious .m3u file.
5b83e41243e20543ddf2cfff77a94b0dMercury Audio Player version 1.21 local SEH overwrite exploit that creates a malicious .pls file.
357fea45c6f6221915f9bec4d0354a81Mercury Audio Player version 1.21 local stack overflow exploit that creates a malicious .b4s file.
f798598afbfab079a41a66f1dbfd80a6Linux 2.6 kernel udev versions below 1.4.1 local privilege escalation exploit.
88076ff8f3391f74c8c6c77d8b8343ffLeap CMS version 0.1.4 suffers from cross site scripting, shell upload, and remote SQL injection vulnerabilities.
23963fa48652ee1f9cea7159884678f4Leap CMS version 0.1.4 remote blind SQL injection exploit.
7221ce3d1645b6ffb2cf7863c6e22685BaoFeng OnBeforeVideoDownload() remote buffer overflow exploit that leverages mps.dll.
c81516cea83c05c09a7077593589ab4cS-CMS version 1.1 suffers from a local file inclusion vulnerability in plugin.php.
398ce81584539fbfe129a7c1c755129eTiger DMS suffers from a remote SQL injection vulnerability that allows for authentication bypass.
d8e63d0d2f66abbc73f6bc67dcb923edZubrag Smart File Download version 1.3 suffers from an arbitrary file download vulnerability.
8ef0c2216ae0efb51beb0bf2ff980555ProjectCMS version 1.0b suffers from a remote SQL injection vulnerability in index.php.
3f048e603eb91f2e2fdf9c06c7b467f1eLitius version 1.0 suffers from a remote SQL injection vulnerability in banner-details.php.
889c8b03d30b38956548e300653583a1mpegable Player version 2.12 local stack overflow proof of concept exploit that creates a malicious .yuv file.
deb56882f8b6864fffe2ccdf8deb861cBaby Web Server version 2.7.2.0 arbitrary file disclosure exploit.
bfd42d9603d8bd03bc3574f88a48c9fcSEC Consult Security Advisory 20090429-0 - LevelOne AMG-2000 Wireless AP Management Gateway suffers from proxy bypass and plain text vulnerabilities.
1acca6056a6eb86cbec0f49635149fa5Symantec Fax Viewer Control in WinFax Pro version 10.03 (DCCFAXVW.DLL) remote buffer overflow exploit.
0383216d374f64d818f5a0761433fa73Autodesk IDrop remote code execution Active-X related exploit.
33738fc96994902b7d66e295f07b9917Quick 'N Easy Web Server version 3.3.5 arbitrary file disclosure exploit.
becc00e2ccc1a67f43e11ee436890c22Google Chrome version 1.0.154.53 "throw exception" remote crash and denial of service exploit.
006378449d255dc12db2c80fbe873d6fMIM:InfiniX version 1.2.003 suffers from multiple remote SQL injection vulnerabilities.
38d2d353380eca5c01021b5fecf728a9webSPELL versions 4.2.0d and below local file disclosure exploit.
ef65f707009b8319ddc617c1bb8f4c5bVisionLMS version 1.0 remote password changing exploit that leverages changePW.php.
993d208fb9a7aad6505212a250b1e5cbLinux 2.6 kernel SCTP FWD memory corruption remote exploit.
a0b77ff6a81e94e1bb927aa43876ea88