VARIoT IoT exploits database

VAR-E-201002-0428 | No CVE | uplusware UplusFtp Multiple Remote Buffer Overflow Vulnerabilities | No EDB ID |
UplusFtp (formerly Easy Ftp Server) is prone to multiple remote buffer-overflow vulnerabilities.
Attackers can exploit these issues to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
UplusFtp 1.7.0.12 is vulnerable; prior versions, including Easy Ftp Server, may also be affected.
VAR-E-201002-0002 |
CVE-2010-0307 CVE-2012-0053 CVE-2011-3368 |
Linux Kernel 2.6.x (x64) - Personality Handling Local Denial of Service - Linux_x86-64 dos Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038, VAR-201002-0694 | EDB ID: 33585 |
Linux Kernel 2.6.x (x64) - Personality Handling Local Denial of Service. CVE-2010-0307CVE-62045 . dos exploit for Linux_x86-64 platform
VAR-E-201002-1339 |
CVE-2010-0307 CVE-2012-0053 CVE-2011-3368 |
Linux Kernel 2.6.x (x64) - Personality Handling Local Denial of Service - Linux_x86-64 dos Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038, VAR-201002-0694 | EDB ID: 33585 |
Linux Kernel 2.6.x (x64) - Personality Handling Local Denial of Service. CVE-2010-0307CVE-62045 . dos exploit for Linux_x86-64 platform
VAR-E-201001-1449 | No CVE | Ingres Database 9.3 - Heap Buffer Overflow - Multiple dos Exploit | EDB ID: 33579 |
Ingres Database 9.3 - Heap Buffer Overflow.. dos exploit for Multiple platform
VAR-E-201001-1423 |
CVE-2009-3739 |
MicroLogix 1100 and 1400 Controllers Multiple Vulnerabilities
Related entries in the VARIoT vulnerabilities database: VAR-201001-0014 | No EDB ID |
MicroLogix 1100 and 1400 Controllers are prone to multiple vulnerabilities.
Attackers may exploit these issues to gain unauthorized access to the programmable logic controller (PLC). Successful exploits will allow attackers to compromise affected devices. Other attacks are also possible.
VAR-E-201001-1551 | No CVE | SAP MaxDB Unspecified Information Disclosure and Denial of Service Vulnerabilities | No EDB ID |
SAP MaxDB is prone to an unspecified information-disclosure vulnerability and an unspecified denial-of-service vulnerability.
Very few details are currently available regarding these issues. We will update this BID as more information emerges.
Attackers can exploit these issues to a cause a denial-of-service condition or obtain sensitive information.
SAP MaxDB 7.6.06 is vulnerable; other versions any also be affected.
VAR-E-201001-0481 | No CVE | DeltaScripts PHP Links 1.0 Cross Site Scripting | No EDB ID |
DeltaScripts PHP Links version 1.0 suffers from a cross site scripting vulnerability.
VAR-E-201001-1189 | No CVE | DELTAScripts PHP Links 1.0 - 'email' Cross-Site Scripting - PHP webapps Exploit | EDB ID: 33484 |
DELTAScripts PHP Links 1.0 - 'email' Cross-Site Scripting.. webapps exploit for PHP platform
VAR-E-201001-1162 | No CVE | D-Link Multiple Routers HNAP Protocol Security Bypass Vulnerability | No EDB ID |
Multiple D-Link routers are prone to a security-bypass vulnerability.
Remote attackers can exploit this issue to bypass security restrictions and access certain administrative functions.
This issue affects the following routers:
DI-524
DIR-628
DIR-655
VAR-E-201001-0525 | No CVE | DeltaScripts PHP Links 'index.php' SQL Injection Vulnerability | No EDB ID |
DeltaScripts PHP Links is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
VAR-E-200912-0008 |
CVE-2009-3555 CVE-2012-0053 CVE-2011-3368 |
TLS - Renegotiation - Multiple remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-200911-0398, VAR-201201-0038 | EDB ID: 10579 |
TLS - Renegotiation. CVE-2009-3555 . remote exploit for Multiple platform
VAR-E-200912-1885 |
CVE-2009-3555 CVE-2012-0053 CVE-2011-3368 |
TLS - Renegotiation - Multiple remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-200911-0398, VAR-201201-0038 | EDB ID: 10579 |
TLS - Renegotiation. CVE-2009-3555 . remote exploit for Multiple platform
VAR-E-200912-0372 | No CVE | D-Link DIR-615 'apply.cgi' Security Bypass Vulnerability | No EDB ID |
D-Link DIR-615 is is prone to a security-bypass vulnerability.
Remote attackers can exploit this issue to bypass security restrictions and access certain administrative functions.
VAR-E-200912-0107 |
CVE-2009-3563 |
NTP mode 7 MODE_PRIVATE Packet Remote Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-200912-0769 | No EDB ID |
NTP is prone to a remote denial-of-service vulnerability because it fails to properly handle certain incoming network packets.
An attacker can exploit this issue to cause the application to consume excessive CPU resources and fill disk space with log messages.
VAR-E-200911-0275 |
CVE-2009-2631 |
Same-origin policy bypass vulnerabilities in several VPN
Related entries in the VARIoT vulnerabilities database: VAR-200912-0424 | No EDB ID |
VAR-E-200911-0049 |
CVE-2009-4117 | MuPDF < 20091125231942 - 'pdf_shade4.c' Multiple Stack Buffer Overflows - Windows local Exploit | EDB ID: 10244 |
MuPDF < 20091125231942 - 'pdf_shade4.c' Multiple Stack Buffer Overflows. CVE-2009-4117CVE-60609 . local exploit for Windows platform
VAR-E-200911-0073 |
CVE-2007-5603 |
SonicWALL SSL-VPN - NetExtender ActiveX Control Buffer Overflow (Metasploit) - Windows remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-200711-0278 | EDB ID: 16616 |
SonicWALL SSL-VPN - NetExtender ActiveX Control Buffer Overflow (Metasploit). CVE-2007-5603CVE-39069 . remote exploit for Windows platform
VAR-E-200911-0011 |
CVE-2009-3555 CVE-2012-0053 CVE-2011-3368 |
Mozilla NSS - NULL Character CA SSL Certificate Validation Security Bypass - Multiple remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-200911-0398, VAR-201201-0038 | EDB ID: 10071 |
Mozilla NSS - NULL Character CA SSL Certificate Validation Security Bypass. CVE-2009-3555CVE-59970 . remote exploit for Multiple platform
VAR-E-200911-0655 |
CVE-2009-3555 CVE-2012-0053 CVE-2011-3368 |
Mozilla NSS - NULL Character CA SSL Certificate Validation Security Bypass - Multiple remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-200911-0398, VAR-201201-0038 | EDB ID: 10071 |
Mozilla NSS - NULL Character CA SSL Certificate Validation Security Bypass. CVE-2009-3555CVE-59970 . remote exploit for Multiple platform
VAR-E-200910-0147 |
CVE-2009-5039 |
Cisco IOS 'gk_circuit_info_do_in_acf()' Function H.323 Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201101-0006 | No EDB ID |
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause the affected device to consume an excessive amount of memory, denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCsz72535.