VARIoT IoT exploits database

VAR-E-201009-1158 |
CVE-2010-2829 |
Cisco IOS CVE-2010-2829 H.323 Unspecified Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201009-0126 | No EDB ID |
Cisco IOS is prone to an unspecified remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected device to reload, denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCtd33567.
VAR-E-201009-0951 |
CVE-2010-2831 |
Cisco IOS NAT Functionality Session Initiation Protocol Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201009-0067 | No EDB ID |
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit these issues to cause an affected device to crash, denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCtf17624.
VAR-E-201009-0741 |
CVE-2010-2832 |
Cisco IOS NAT Functionality H.323 Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201009-0068 | No EDB ID |
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected device to reload, denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCtf91428.
VAR-E-201009-0622 |
CVE-2010-2830 |
Cisco IOS Internet Group Management Protocol Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201009-0127 | No EDB ID |
Cisco IOS is prone to a remote denial-of-service vulnerability in the Internet Group Management Protocol (IGMP).
An attacker can exploit this issue to cause an affected device to reload, denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCte14603.
VAR-E-201009-0366 |
CVE-2010-2828 |
Cisco IOS CVE-2010-2828 H.323 Unspecified Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201009-0125 | No EDB ID |
Cisco IOS is prone to an unspecified remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected device to reload, denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCtc73759.
VAR-E-201009-0217 |
CVE-2010-2835 |
Cisco IOS And Unified Communications Manager (CVE-2010-2835) Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201009-0066 | No EDB ID |
Cisco IOS and Unified Communications Manager are prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause an interruption in voice services or cause the affected device to reload, denying service to legitimate users.
This issue is tracked by Cisco Bug IDs CSCta31358 and CSCta20040.
VAR-E-201009-0055 |
CVE-2010-2834 |
Cisco IOS And Unified Communications Manager (CVE-2010-2834) Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201009-0065 | No EDB ID |
Cisco IOS and Unified Communications Manager are prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause an interruption in voice services or cause the affected device to reload, denying service to legitimate users.
This issue is tracked by Cisco Bug IDs CSCtf14987 and CSCtf72678.
VAR-E-201009-0035 |
CVE-2010-0886 CVE-2012-0053 CVE-2011-3368 |
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit) - Windows remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038 | EDB ID: 16585 |
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit). CVE-2010-0886CVE-63648 . remote exploit for Windows platform
VAR-E-201009-1223 |
CVE-2010-0886 CVE-2012-0053 CVE-2011-3368 |
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit) - Windows remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038 | EDB ID: 16585 |
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit). CVE-2010-0886CVE-63648 . remote exploit for Windows platform
VAR-E-201009-0028 |
CVE-2010-0838 CVE-2012-0053 CVE-2011-3368 |
Java 6.19 CMM readMabCurveData - Remote Stack Overflow - Windows remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038 | EDB ID: 15056 |
Java 6.19 CMM readMabCurveData - Remote Stack Overflow. CVE-2010-0838 . remote exploit for Windows platform
VAR-E-201009-1224 |
CVE-2010-0838 CVE-2012-0053 CVE-2011-3368 |
Java 6.19 CMM readMabCurveData - Remote Stack Overflow - Windows remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038 | EDB ID: 15056 |
Java 6.19 CMM readMabCurveData - Remote Stack Overflow. CVE-2010-0838 . remote exploit for Windows platform
VAR-E-201009-0029 |
CVE-2010-3081 CVE-2012-0053 CVE-2011-3368 |
Linux Kernel 2.6.27 < 2.6.36 (RedHat x86-64) - 'compat' Local Privilege Escalation - Linux_x86-64 local Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038 | EDB ID: 15024 |
Linux Kernel 2.6.27 < 2.6.36 (RedHat x86-64) - 'compat' Local Privilege Escalation. CVE-2010-3081CVE-68213 . local exploit for Linux_x86-64 platform
VAR-E-201009-1222 |
CVE-2010-3081 CVE-2012-0053 CVE-2011-3368 |
Linux Kernel 2.6.27 < 2.6.36 (RedHat x86-64) - 'compat' Local Privilege Escalation - Linux_x86-64 local Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038 | EDB ID: 15024 |
Linux Kernel 2.6.27 < 2.6.36 (RedHat x86-64) - 'compat' Local Privilege Escalation. CVE-2010-3081CVE-68213 . local exploit for Linux_x86-64 platform
VAR-E-201009-1071 |
CVE-2010-0574 |
Cisco Wireless LAN Controller IKE Packet Handling Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201009-0017 | No EDB ID |
Cisco Wireless LAN Controller is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause an affected device to reload, denying service to legitimate users.
This issue is tracked by Cisco Bug ID CSCta56653.
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsq24002
VAR-E-201009-0846 | No CVE | Hitachi JP1/NETM/Remote Control Agent File Transfer Feature Security Bypass Vulnerability | No EDB ID |
Hitachi JP1/NETM/Remote Control Agent is prone to a security-bypass vulnerability.
Remote attackers can exploit this issue to bypass security restrictions and gain unauthorized access. Other attacks may also be possible.
VAR-E-201009-0065 |
CVE-2010-3007 |
HP Data Protector - DtbClsLogin Buffer Overflow (Metasploit) - Windows remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201009-0282 | EDB ID: 23290 |
HP Data Protector - DtbClsLogin Buffer Overflow (Metasploit). CVE-2010-3007CVE-67973 . remote exploit for Windows platform
VAR-E-201009-1154 | No CVE | Open Handset Alliance Android Local Privilege Escalation Vulnerability | No EDB ID |
Open Handset Alliance Android is prone to a privilege-escalation vulnerability.
Successfully exploiting this issue can allow attackers to elevate privileges, leading to a complete compromise of the device.
VAR-E-201009-0233 | No CVE | Sony PlayStation 3 (PS3) Local USB Buffer Overflow Vulnerability | No EDB ID |
Sony PlayStation 3 (PS3) is prone to a local buffer-overflow vulnerability because the device fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to jailbreak an affected device and execute arbitrary code using a specially crafted USB dongle. Failed exploit attempts will result in a denial-of-service condition.
Sony PlayStation 3 (PS3) software version 3.41 and prior is vulnerable.
VAR-E-201009-0069 | No CVE | Accton-based Switches Backdoor Password Vulnerability | No EDB ID |
Accton-based switches are prone to a security vulnerability due to the existence of a backdoor password.
Successful exploits will allow remote attackers to perform brute-force attacks and obtain the password used for HTTP, SSH, and Telnet services.
The following products are vulnerable:
3Com 3812
3Com 3870
EdgeCore ES4649
Dell PowerConnect 5224
Other products from multiple vendors that re-brand Accton switches may also be affected.
VAR-E-201008-0224 | No CVE | Hycus CMS 1.0.1 Cross Site Request Forgery | No EDB ID |
Hycus CMS version 1.0.1 suffers from multiple cross site request forgery vulnerabilities.