VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-201002-0428 No CVE uplusware UplusFtp Multiple Remote Buffer Overflow Vulnerabilities No EDB ID
UplusFtp (formerly Easy Ftp Server) is prone to multiple remote buffer-overflow vulnerabilities. Attackers can exploit these issues to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition. UplusFtp 1.7.0.12 is vulnerable; prior versions, including Easy Ftp Server, may also be affected.
VAR-E-201002-0002 CVE-2010-0307
CVE-2012-0053
CVE-2011-3368
Linux Kernel 2.6.x (x64) - Personality Handling Local Denial of Service - Linux_x86-64 dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038, VAR-201002-0694
EDB ID: 33585
Linux Kernel 2.6.x (x64) - Personality Handling Local Denial of Service. CVE-2010-0307CVE-62045 . dos exploit for Linux_x86-64 platform
VAR-E-201002-1339 CVE-2010-0307
CVE-2012-0053
CVE-2011-3368
Linux Kernel 2.6.x (x64) - Personality Handling Local Denial of Service - Linux_x86-64 dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038, VAR-201002-0694
EDB ID: 33585
Linux Kernel 2.6.x (x64) - Personality Handling Local Denial of Service. CVE-2010-0307CVE-62045 . dos exploit for Linux_x86-64 platform
VAR-E-201001-1449 No CVE Ingres Database 9.3 - Heap Buffer Overflow - Multiple dos Exploit EDB ID: 33579
Ingres Database 9.3 - Heap Buffer Overflow.. dos exploit for Multiple platform
VAR-E-201001-1423 CVE-2009-3739
MicroLogix 1100 and 1400 Controllers Multiple Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-201001-0014
No EDB ID
MicroLogix 1100 and 1400 Controllers are prone to multiple vulnerabilities. Attackers may exploit these issues to gain unauthorized access to the programmable logic controller (PLC). Successful exploits will allow attackers to compromise affected devices. Other attacks are also possible.
VAR-E-201001-1551 No CVE SAP MaxDB Unspecified Information Disclosure and Denial of Service Vulnerabilities No EDB ID
SAP MaxDB is prone to an unspecified information-disclosure vulnerability and an unspecified denial-of-service vulnerability. Very few details are currently available regarding these issues. We will update this BID as more information emerges. Attackers can exploit these issues to a cause a denial-of-service condition or obtain sensitive information. SAP MaxDB 7.6.06 is vulnerable; other versions any also be affected.
VAR-E-201001-0481 No CVE DeltaScripts PHP Links 1.0 Cross Site Scripting No EDB ID
DeltaScripts PHP Links version 1.0 suffers from a cross site scripting vulnerability.
VAR-E-201001-1189 No CVE DELTAScripts PHP Links 1.0 - 'email' Cross-Site Scripting - PHP webapps Exploit EDB ID: 33484
DELTAScripts PHP Links 1.0 - 'email' Cross-Site Scripting.. webapps exploit for PHP platform
VAR-E-201001-1162 No CVE D-Link Multiple Routers HNAP Protocol Security Bypass Vulnerability No EDB ID
Multiple D-Link routers are prone to a security-bypass vulnerability. Remote attackers can exploit this issue to bypass security restrictions and access certain administrative functions. This issue affects the following routers: DI-524 DIR-628 DIR-655
VAR-E-201001-0525 No CVE DeltaScripts PHP Links 'index.php' SQL Injection Vulnerability No EDB ID
DeltaScripts PHP Links is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
VAR-E-200912-0008 CVE-2009-3555
CVE-2012-0053
CVE-2011-3368
TLS - Renegotiation - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-200911-0398, VAR-201201-0038
EDB ID: 10579
TLS - Renegotiation. CVE-2009-3555 . remote exploit for Multiple platform
VAR-E-200912-1885 CVE-2009-3555
CVE-2012-0053
CVE-2011-3368
TLS - Renegotiation - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-200911-0398, VAR-201201-0038
EDB ID: 10579
TLS - Renegotiation. CVE-2009-3555 . remote exploit for Multiple platform
VAR-E-200912-0372 No CVE D-Link DIR-615 'apply.cgi' Security Bypass Vulnerability No EDB ID
D-Link DIR-615 is is prone to a security-bypass vulnerability. Remote attackers can exploit this issue to bypass security restrictions and access certain administrative functions.
VAR-E-200912-0107 CVE-2009-3563
NTP mode 7 MODE_PRIVATE Packet Remote Denial of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200912-0769
No EDB ID
NTP is prone to a remote denial-of-service vulnerability because it fails to properly handle certain incoming network packets. An attacker can exploit this issue to cause the application to consume excessive CPU resources and fill disk space with log messages.
VAR-E-200911-0275 CVE-2009-2631
Same-origin policy bypass vulnerabilities in several VPN

Related entries in the VARIoT vulnerabilities database: VAR-200912-0424
No EDB ID
VAR-E-200911-0049 CVE-2009-4117
MuPDF < 20091125231942 - 'pdf_shade4.c' Multiple Stack Buffer Overflows - Windows local Exploit EDB ID: 10244
MuPDF < 20091125231942 - 'pdf_shade4.c' Multiple Stack Buffer Overflows. CVE-2009-4117CVE-60609 . local exploit for Windows platform
VAR-E-200911-0073 CVE-2007-5603
SonicWALL SSL-VPN - NetExtender ActiveX Control Buffer Overflow (Metasploit) - Windows remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200711-0278
EDB ID: 16616
SonicWALL SSL-VPN - NetExtender ActiveX Control Buffer Overflow (Metasploit). CVE-2007-5603CVE-39069 . remote exploit for Windows platform
VAR-E-200911-0011 CVE-2009-3555
CVE-2012-0053
CVE-2011-3368
Mozilla NSS - NULL Character CA SSL Certificate Validation Security Bypass - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-200911-0398, VAR-201201-0038
EDB ID: 10071
Mozilla NSS - NULL Character CA SSL Certificate Validation Security Bypass. CVE-2009-3555CVE-59970 . remote exploit for Multiple platform
VAR-E-200911-0655 CVE-2009-3555
CVE-2012-0053
CVE-2011-3368
Mozilla NSS - NULL Character CA SSL Certificate Validation Security Bypass - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-200911-0398, VAR-201201-0038
EDB ID: 10071
Mozilla NSS - NULL Character CA SSL Certificate Validation Security Bypass. CVE-2009-3555CVE-59970 . remote exploit for Multiple platform
VAR-E-200910-0147 CVE-2009-5039
Cisco IOS 'gk_circuit_info_do_in_acf()' Function H.323 Denial of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201101-0006
No EDB ID
Cisco IOS is prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to cause the affected device to consume an excessive amount of memory, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCsz72535.