trust is easily compromised
Showing 101 - 125 of 3,056 RSS Feed

Code Execution Files

Bugzilla CSRF / Account Impersonation
Posted Feb 2, 2012
Site bugzilla.org

Bugzilla versions 2.0 to 3.4.13, 3.5.1 to 3.6.7, 3.7.1 to 4.0.3, and 4.1.1 to 4.2rc1 suffer from account impersonation and cross site request forgery vulnerabilities.

tags | advisory, vulnerability, code execution, file inclusion, csrf
advisories | CVE-2012-0448, CVE-2012-0440
MD5 | 5f18baac37e23f9bb6e5a2f1489a4470
Adobe Flash Player Code Execution
Posted Jan 31, 2012
Authored by Abysssec | Site abysssec.com

Adobe Flash Player MP4 SequenceParameterSetNALUnit remote code execution exploit that works against versions 10.3.181.34 and below on XP SP3.

tags | exploit, remote, code execution
advisories | CVE-2011-2140
MD5 | cf02af1c3dc09483a9ca31549d45ec0b
MS12-004 midiOutPlayNextPolyEvent Heap Overflow
Posted Jan 28, 2012
Authored by sinn3r, juan vazquez, Shane Garrett | Site metasploit.com

This Metasploit module exploits a heap overflow vulnerability in the Windows Multimedia Library (winmm.dll). The vulnerability occurs when parsing specially crafted MIDI files. Remote code execution can be achieved by using Windows Media Player's ActiveX control. Exploitation is done by supplying a specially crafted MIDI file with specific events, causing the offset calculation being higher than how much is available on the heap (0x400 allocated by WINMM!winmmAlloc), and then allowing us to either "inc al" or "dec al" a byte. This can be used to corrupt an array (CImplAry) we setup, and force the browser to confuse types from tagVARIANT objects, which leverages remote code execution under the context of the user. At this time, for IE 8 target, JRE (Java Runtime Environment) is required to bypass DEP (Data Execution Prevention). Note: Based on our testing, the vulnerability does not seem to trigger when the victim machine is operated via rdesktop.

tags | exploit, java, remote, overflow, code execution, activex
systems | windows
advisories | CVE-2012-0003, OSVDB-78210
MD5 | e13897802c519c03ae5164b1d2ecb919
EMC NetWorker Buffer Overflow
Posted Jan 26, 2012
Authored by Tal Zeltzer | Site emc.com

EMC NetWorker Server 7.5.x and 7.6.x contain a buffer overflow vulnerability which may possibly be exploited to cause a denial of service or, possibly, arbitrary code execution.

tags | advisory, denial of service, overflow, arbitrary, code execution
advisories | CVE-2012-0395
MD5 | 8f138c228e545ad94a699b74ddf8e3d7
Register Plus 3.5.1 Cross Site Scripting / Code Execution
Posted Jan 26, 2012
Authored by MustLive

Register Plus versions 3.5.1 and below for WordPress suffer from code execution, cross site scripting and path disclosure vulnerabilities.

tags | exploit, vulnerability, code execution, xss
MD5 | 719992bc7507af6bc667c58318c7c250
vBadvanced CMPS 3.2.2 Local File Inclusion / Remote File Inclusion
Posted Jan 25, 2012
Authored by PacketiK

vBadvanced CMPS versions 3.2.2 and below suffer from local file inclusion and remote file inclusion vulnerabilities.

tags | exploit, remote, local, vulnerability, code execution, file inclusion
MD5 | e2be31fe18b36ede34febe2700666d74
NX Web Companion Spoofing Arbitrary Code Execution
Posted Jan 25, 2012
Authored by otr

NX Web Companion suffers from a spoofing vulnerability that may allow for arbitrary code execution.

tags | advisory, web, arbitrary, spoof, code execution
MD5 | 217d5cb4dac721dbdb33b56bf020535d
Debian Security Advisory 2393-1
Posted Jan 25, 2012
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2393-1 - Julien Tinnes reported a buffer overflow in the bip multiuser irc proxy which may allow arbitrary code execution by remote users.

tags | advisory, remote, overflow, arbitrary, code execution
systems | linux, debian
advisories | CVE-2012-0806
MD5 | 37b1895dc25699ccbbbff86aa524f9f1
Symantec PCAnywhere Code Execution
Posted Jan 25, 2012
Authored by Edward Torkington | Site ngssoftware.com

Symantec PCAnywhere version 12.5.x suffers from a code execution vulnerability.

tags | advisory, code execution
MD5 | 060facd3910ac12a61ed8cab17ba77f1
WordPress 3.3.1 Code Execution / Cross Site Scripting
Posted Jan 25, 2012
Authored by Jonathan Claudius | Site trustwave.com

WordPress versions 3.3.1 and below suffer from MySQL username/password disclosure, PHP code execution and cross site scripting vulnerabilities.

tags | exploit, php, vulnerability, code execution, xss
advisories | CVE-2011-4899, CVE-2012-0782, CVE-2011-4898
MD5 | 2ff8651f912a2170669cc231ffd47fb5
miniCMS 1.0 / 2.0 Code Execution
Posted Jan 23, 2012
Authored by Or4nG.M4N

miniCMS versions 1.0 and 2.0 suffer from a remote code execution vulnerability through php code injection.

tags | exploit, remote, php, code execution
MD5 | a9083c8800989e739344d6e9e06904ef
Suhosin PHP Extension Transparent Cookie Encryption Stack Buffer Overflow
Posted Jan 19, 2012
Authored by Stefan Esser

A possible stack buffer overflow in Suhosin extension's transparent cookie encryption that can only be triggered in an uncommon and weakened Suhosin configuration can lead to arbitrary remote code execution, if the FORTIFY_SOURCE compile option was not used when Suhosin was compiled. Versions 0.9.32.1 and below are affected.

tags | exploit, remote, overflow, arbitrary, code execution
MD5 | 606156cd50168f1f52ef5ba71487136d
HP Easy Printer Care XMLCacheMgr Class ActiveX Control Remote Code Execution
Posted Jan 18, 2012
Authored by Andrea Micalizzi, juan vazquez | Site metasploit.com

This Metasploit module allows remote attackers to place arbitrary files on a users file system by abusing the "CacheDocumentXMLWithId" method from the "XMLCacheMgr" class in the HP Easy Printer HPTicketMgr.dll ActiveX Control (HPTicketMgr.dll 2.7.2.0). Code execution can be achieved by first uploading the payload to the remote machine embedding a vbs file, and then upload another mof file, which enables Windows Management Instrumentation service to execute the vbs. Please note that this module currently only works for Windows before Vista.

tags | exploit, remote, arbitrary, code execution, activex
systems | windows
advisories | CVE-2011-4786
MD5 | b01ade0319dd4987b8285b4f21c4ed2e
BS.Player 2.57 Buffer Overflow Exploit (Unicode SEH)
Posted Jan 18, 2012
Authored by Chris Gabriel, C4SS!0 G0M3S | Site metasploit.com

This Metasploit module exploits a buffer overflow in BS.Player 2.57. When the playlist import is used to import a specially crafted m3u file, a buffer overflow occurs allowing arbitrary code execution.

tags | exploit, overflow, arbitrary, code execution
MD5 | 7c67522cd28b05fc5d13a63e8a75b419
Debian Security Advisory 2388-1
Posted Jan 16, 2012
Authored by Debian | Site debian.org

Debian Linux Security Advisory 2388-1 - Several vulnerabilities were discovered in t1lib, a Postscript Type 1 font rasterizer library, some of which might lead to code execution through the opening of files embedding bad fonts.

tags | advisory, vulnerability, code execution
systems | linux, debian
advisories | CVE-2010-2642, CVE-2011-0433, CVE-2011-0764, CVE-2011-1552, CVE-2011-1553, CVE-2011-1554
MD5 | 459eacf876f4aa0d27cd33cdfa2c4e04
Zero Day Initiative Advisory 12-016
Posted Jan 13, 2012
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 12-016 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Diagnostics server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the way the HP Diagnostics server handles incoming packets with 0x00000000 as the first 32-bit value. The magentservice.exe process listens on port 23472 by default. It will eventually take that first dword, decrease it by one and use it as a size value to copy data into a stack buffer. The resulting stack-based buffer overflow can result in remote code execution under the system user.

tags | advisory, remote, overflow, arbitrary, code execution
advisories | CVE-2011-4789
MD5 | 9bf396821847a21563fc931859e050be
Mandriva Linux Security Advisory 2012-004
Posted Jan 13, 2012
Authored by Mandriva | Site mandriva.com

Mandriva Linux Security Advisory 2012-004 - Multiple vulnerabilities has been found and corrected in t1lib. A heap-based buffer overflow flaw was found in the way AFM font file parser, used for rendering of DVI files, in GNOME evince document viewer and other products, processed line tokens from the given input stream. A remote attacker could provide a DVI file, with embedded specially-crafted font file, and trick the local user to open it with an application using the AFM font parser, leading to that particular application crash or, potentially, arbitrary code execution with the privileges of the user running the application. Various other issues were also addressed.

tags | advisory, remote, overflow, arbitrary, local, vulnerability, code execution
systems | linux, mandriva
advisories | CVE-2011-0433, CVE-2011-1552, CVE-2011-1553, CVE-2011-1554
MD5 | f4d6c3cb08dde11fdb1306e368d59d26
Zero Day Initiative Advisory 12-013
Posted Jan 13, 2012
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 12-013 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of HP Easy Printer Care. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the XMLCacheMgr class ActiveX control (CLSID 6F255F99-6961-48DC-B17E-6E1BCCBC0EE3). The CacheDocumentXMLWithId() method is vulnerable to directory traversal and arbitrary write, which allows an attacker to write malicious content to the filesystem. A remote attacker could leverage this vulnerability to gain code execution under the context of the web browser.

tags | advisory, remote, web, arbitrary, code execution, activex
advisories | CVE-2011-4786
MD5 | 37c6d04112e9302eb6503a8c143322a0
GreenBrowser Searchbar Double Free
Posted Jan 13, 2012
Site nipc.org.cn

GreenBrowser suffers from a double free vulnerability in an iframe object that can lead to arbitrary code execution. Versions 6.0.1002 and below are affected.

tags | advisory, arbitrary, code execution
MD5 | d1d1d8ce817e32c30a433496bc21283e
Kayako Support Suite 3.70.02 PHP Code Execution
Posted Jan 12, 2012
Authored by Alexander Zaitsev | Site ptsecurity.com

Kayako Support Suite versions 3.70.02-stable and below suffer from a PHP code execution vulnerability.

tags | exploit, php, code execution
MD5 | 65bcefe68572462a1ca96beb831ff69b
Novell Netware XNFS caller_name xdrDecodeString Code Execution
Posted Jan 11, 2012
Authored by Francis Provencher

Novell Netware XNFS caller_name xdrDecodeString remote code execution exploit. Version 6.5 SP8 is affected.

tags | exploit, remote, code execution
MD5 | 003d454d67d459d784f5a28fd02254cf
SAPID 1.2.3 Remote File Inclusion
Posted Jan 8, 2012
Authored by Opa Yong

SAPID version 1.2.3 Stable suffers from a remote file inclusion vulnerability.

tags | exploit, remote, code execution, file inclusion
MD5 | 9e24af074298ce81724f7fedef72600c
Novell Netware XNFS.NLM NFS Rename Remote Code Execution
Posted Jan 7, 2012
Authored by Francis Provencher

Novell Netware version 6.5 SP8 suffers from a XNFS.NLM NFS Rename remote code execution vulnerability.

tags | exploit, remote, code execution
MD5 | 932cbf32f536d7915c5001d7b70f4ad7
Novell Netware XNFS.NLM STAT Notify Remote Code Execution
Posted Jan 7, 2012
Authored by Francis Provencher

Novell Netware version 6.5 SP8 suffers from a XNFS.NLM STAT Notify remote code execution vulnerability.

tags | exploit, remote, code execution
MD5 | e949872ec1d486d378b559f2ae10cbf2
Zero Day Initiative Advisory 12-005
Posted Jan 6, 2012
Authored by Tipping Point | Site zerodayinitiative.com

Zero Day Initiative Advisory 12-05 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Apple QuickTime Player. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within how the application decodes video samples encoded with the RLE codec. When decompressing the sample, the application will fail to accommodate for the canvas the sample is rendered into. This can cause a buffer overflow and thus can be taken advantage of in order to gain code execution under the context of the application.

tags | advisory, remote, overflow, arbitrary, code execution
systems | apple
advisories | CVE-2011-3248
MD5 | e2313aba0e79de102b33fcc75a2e53eb
Page 5 of 123
Back34567Next

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    11 Files
  • 27
    May 27th
    8 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close