VARIoT IoT exploits database

VAR-E-200904-0363 |
CVE-2009-4914 CVE-2009-4912 CVE-2009-4910 CVE-2009-4915 CVE-2009-4916 CVE-2009-4913 CVE-2009-4920 CVE-2009-4921 CVE-2009-4911 CVE-2009-4918 CVE-2009-4923 CVE-2009-4919 CVE-2009-4922 CVE-2009-4917 |
Cisco Adaptive Security Appliances (ASA) 5580 Series Multiple Security Vulnerabilities
Related entries in the VARIoT vulnerabilities database: VAR-201006-0015, VAR-201006-0016, VAR-201006-0017, VAR-201006-0018, VAR-201006-0019, VAR-201006-0021, VAR-201006-0022, VAR-201006-0023, VAR-201006-0024, VAR-201006-0025, VAR-201006-0026, VAR-201006-0027, VAR-201006-0014, VAR-201006-0020 | No EDB ID |
Cisco ASA 5580 series security appliances are prone to multiple security vulnerabilities. The vulnerabilities include multiple denial-of-service vulnerabilities, multiple buffer-overflow vulnerabilities, authentication-bypass vulnerabilities and a cross-site scripting vulnerability.
Exploiting these issues could allow an attacker to deny service to legitimate users, bypass security restrictions and gain unauthorized access, execute arbitrary script code, or steal cookie-based authentication credentials. Other attacks may also be possible.
Cisco ASA 5580 series security appliances with software prior to 8.1(2) are vulnerable.
VAR-E-200903-0140 |
CVE-2007-4475 |
SAP MaxDB 7.4/7.6 - 'webdbm' Multiple Cross-Site Scripting Vulnerabilities - Windows remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-200904-0568 | EDB ID: 32879 |
SAP MaxDB 7.4/7.6 - 'webdbm' Multiple Cross-Site Scripting Vulnerabilities. CVE-2007-4475CVE-53066 . remote exploit for Windows platform
VAR-E-200903-0213 |
CVE-2009-1220 |
Cisco ASA Appliance 7.x/8.0 WebVPN - Cross-Site Scripting - Hardware remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-200904-0299 | EDB ID: 32878 |
Cisco ASA Appliance 7.x/8.0 WebVPN - Cross-Site Scripting. CVE-2009-1220CVE-53147 . remote exploit for Hardware platform
VAR-E-200903-0139 |
CVE-2007-4475 |
SAP AG SAPgui EAI WebViewer3D - Remote Buffer Overflow (Metasploit) - Windows remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-200904-0568 | EDB ID: 16575 |
SAP AG SAPgui EAI WebViewer3D - Remote Buffer Overflow (Metasploit). CVE-2007-4475CVE-53066 . remote exploit for Windows platform
VAR-E-200903-0283 |
CVE-2009-0636 |
Cisco IOS Session Initiation Protocol Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-200903-0281 | No EDB ID |
Cisco IOS is prone to a remote denial-of-service vulnerability.
An attacker can exploit these issues to cause an affected device to crash, denying service to legitimate users.
This issue is being tracked by Cisco Bug ID CSCsu11522.
VAR-E-200902-0505 |
CVE-2009-0621 CVE-2009-0620 CVE-2009-0625 CVE-2009-0624 CVE-2009-0623 CVE-2009-0622 |
Multiple Cisco ACE Products Multiple Remote Vulnerabilities
Related entries in the VARIoT vulnerabilities database: VAR-200902-0540, VAR-200902-0541, VAR-200902-0536, VAR-200902-0537, VAR-200902-0538, VAR-200902-0539 | No EDB ID |
Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine are prone to multiple remote vulnerabilities:
- Multiple authentication-bypass issues
- A remote privilege-escalation issue
- Multiple denial-of-service issues
Attackers can exploit these issues to execute arbitrary commands, gain administrative access, and cause denial-of-service conditions. Other attacks are also possible.
VAR-E-200902-0516 |
CVE-2009-0059 CVE-2009-0062 CVE-2009-0058 CVE-2009-0061 |
Multiple Cisco Wireless LAN Controllers Multiple Remote Vulnerabilities
Related entries in the VARIoT vulnerabilities database: VAR-200902-0479, VAR-200902-0481, VAR-200902-0480, VAR-200902-0478 | No EDB ID |
Multiple Cisco Wireless LAN Controllers are prone to these remote vulnerabilities:
- Multiple denial-of-service vulnerabilities
- A remote privilege-escalation vulnerability
Remote attackers can exploit these issues to gain administrative rights on an affected device or crash the device, denying service to legitimate users.
The following devices are affected:
Cisco 4400 Series Wireless LAN Controllers
Cisco Catalyst 6500 Series/7600 Series Wireless Services Module (WiSM)
Cisco Catalyst 3750 Series Integrated Wireless LAN Controllers
VAR-E-200901-1013 |
CVE-2009-0244 |
HTC / Android OBEX FTP Service Directory Traversal
Related entries in the VARIoT vulnerabilities database: VAR-200901-0408 | No EDB ID |
HTC devices running Android versions 2.1 and 2.2 suffer from a directory traversal vulnerability in the OBEX FTP service. Full details provided.
VAR-E-200901-0592 | No CVE | Multiple Sagem F@st Routers 'restoreinfo.cgi' Unauthorized Access Vulnerability | No EDB ID |
Multiple Sagem F@st routers are prone to an unauthorized-access vulnerability.
Attackers can exploit this issue to reset the router, possibly resulting in denial-of-service conditions. Other security implications that could aid in further attacks may also occur.
The following routers are affected:
Sagem F@st 1200
Sagem F@st 1240
Sagem F@st 1400
Sagem F@st 1400W
Sagem F@st 1500
Sagem F@st 1500-WG
Sagem F@st 2404
VAR-E-200901-0317 |
CVE-2008-3821 |
Cisco IOS 12.x - HTTP Server Multiple Cross-Site Scripting Vulnerabilities - Hardware remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-200901-0448 | EDB ID: 32723 |
Cisco IOS 12.x - HTTP Server Multiple Cross-Site Scripting Vulnerabilities. CVE-2008-3821CVE-51394CVE-51393 . remote exploit for Hardware platform
VAR-E-200901-0112 |
CVE-2008-4827 |
Multiple Vendor SizerOne ActiveX Control 'AddTab' Method Buffer Overflow Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-200901-0399 | No EDB ID |
The SizerOne ActiveX control used in products by multiple vendors is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied data before copying it into an insufficiently sized memory buffer.
An attacker can exploit this issue to execute arbitrary code within the context of the application that uses the ActiveX control (typically Internet Explorer). Failed exploit attempts will result in denial-of-service conditions.
VAR-E-200812-0006 |
CVE-2008-5416 CVE-2008-4270 CVE-2012-0053 CVE-2011-3368 |
Microsoft SQL Server - 'sp_replwritetovarbin()' Heap Overflow - Windows local Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038 | EDB ID: 7501 |
Microsoft SQL Server - 'sp_replwritetovarbin()' Heap Overflow. CVE-50589CVE-2008-5416CVE-2008-4270 . local exploit for Windows platform
VAR-E-200812-1342 |
CVE-2008-5416 CVE-2008-4270 CVE-2012-0053 CVE-2011-3368 |
Microsoft SQL Server - 'sp_replwritetovarbin()' Heap Overflow - Windows local Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038 | EDB ID: 7501 |
Microsoft SQL Server - 'sp_replwritetovarbin()' Heap Overflow. CVE-50589CVE-2008-5416CVE-2008-4270 . local exploit for Windows platform
VAR-E-200812-1307 | No CVE | Rumpus FTP Server Command Argument Remote Buffer Overflow Vulnerability | No EDB ID |
Maxum Rumpus is prone to a remote buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with the privileges of the user running the affected application, possibly with root privileges. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Rumpus 6.0.1 are vulnerable.
VAR-E-200812-0133 | No CVE | Rumpus FTP Server HTTP Command Remote Denial of Service Vulnerability | No EDB ID |
Maxum Rumpus FTP Server is prone to a remote denial-of-service vulnerability.
This issue allows remote attackers to crash affected servers, denying service to legitimate users. Given the nature of this issue, attackers may also be able to run arbitrary code within the context of the vulnerable application, but this has not been confirmed.
Versions prior to Rumpus 6.0.1 are vulnerable.
VAR-E-200811-0117 |
CVE-2008-6720 |
DELTAScripts PHP Links 1.3 - Authentication Bypass - PHP webapps Exploit
Related entries in the VARIoT vulnerabilities database: VAR-200904-0147 | EDB ID: 7024 |
DELTAScripts PHP Links 1.3 - Authentication Bypass. CVE-53672CVE-2008-6720 . webapps exploit for PHP platform
VAR-E-200811-1138 |
CVE-2008-4963 |
Cisco IOS and CatOS VLAN Trunking Protocol Packet Handling Denial Of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-200811-0138 | No EDB ID |
Cisco IOS and CatOS are prone to a remote denial-of-service vulnerability.
An attacker can exploit this issue to cause affected devices to restart, effectively denying service to legitimate users.
This issue is being tracked by Cisco Bug IDs CSCsv05934 and CSCsv11741.
VAR-E-200810-0809 |
CVE-2008-4309 |
Net-SNMP GETBULK Remote Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-200810-0643 | No EDB ID |
Net-SNMP is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue allows remote attackers to cause denial-of-service conditions.
This issue affects versions *prior to* the following:
Net-SNMP 5.2.5.1
Net-SNMP 5.3.2.3
Net-SNMP 5.4.2.1
VAR-E-200810-0978 | No CVE | Hitachi JP1/File Transmission Server/FTP Unspecified Denial Of Service Vulnerability | No EDB ID |
Hitachi JP1/File Transmission Server/FTP is prone to an unspecified denial-of-service vulnerability because it fails to properly handle unexpected data.
Attackers can exploit this issue to cause the connection to be reset or to stop FTP services.
VAR-E-200809-0693 |
CVE-2008-4322 |
DATAC RealWin SCADA Server 2.0 - Remote Stack Buffer Overflow - Windows remote Exploit
Related entries in the VARIoT vulnerabilities database: VAR-200809-0422 | EDB ID: 32426 |
DATAC RealWin SCADA Server 2.0 - Remote Stack Buffer Overflow.. remote exploit for Windows platform