VARIoT IoT exploits database

VAR-E-201608-0575 |
CVE-2016-7454 |
Xfinity Gateway (Technicolor DPC3941T) - Cross-Site Request Forgery - Hardware webapps Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201612-0237 | EDB ID: 40982 |
Xfinity Gateway (Technicolor DPC3941T) - Cross-Site Request Forgery. CVE-2016-7454 . webapps exploit for Hardware platform
VAR-E-201608-0094 | No CVE | NUUO NVRmini 2 3.0.8 - Cross-Site Request Forgery (Add Admin) - PHP webapps Exploit | EDB ID: 40210 |
NUUO NVRmini 2 3.0.8 - Cross-Site Request Forgery (Add Admin).. webapps exploit for PHP platform
VAR-E-201608-0047 | No CVE | NUUO NVRmini 2 3.0.8 - Multiple OS Command Injections - PHP webapps Exploit | EDB ID: 40212 |
NUUO NVRmini 2 3.0.8 - Multiple OS Command Injections.. webapps exploit for PHP platform
VAR-E-201608-0131 | No CVE | NUUO NVRmini 2 3.0.8 - Arbitrary File Deletion - PHP webapps Exploit | EDB ID: 40214 |
NUUO NVRmini 2 3.0.8 - Arbitrary File Deletion.. webapps exploit for PHP platform
VAR-E-201608-0008 | No CVE | NUUO NVRmini 2 3.0.8 - Local File Disclosure - PHP webapps Exploit | EDB ID: 40211 |
NUUO NVRmini 2 3.0.8 - Local File Disclosure.. webapps exploit for PHP platform
VAR-E-201608-0132 | No CVE | NUUO NVRmini 2 3.0.8 - 'strong_user.php' Backdoor Remote Shell Access - PHP webapps Exploit | EDB ID: 40215 |
NUUO NVRmini 2 3.0.8 - 'strong_user.php' Backdoor Remote Shell Access.. webapps exploit for PHP platform
VAR-E-201608-0211 | No CVE | NUUO NVRmini 2 3.0.8 - Remote Command Injection (Shellshock) - CGI webapps Exploit | EDB ID: 40213 |
NUUO NVRmini 2 3.0.8 - Remote Command Injection (Shellshock).. webapps exploit for CGI platform
VAR-E-201608-0245 | No CVE | NUUO NVRmini 2 3.0.8 - Remote Code Execution - PHP webapps Exploit | EDB ID: 40209 |
NUUO NVRmini 2 3.0.8 - Remote Code Execution.. webapps exploit for PHP platform
VAR-E-201608-0513 |
CVE-2016-6525 |
MuPDF CVE-2016-6525 Heap Corruption Denial of Service Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201609-0097 | No EDB ID |
MuPDF is prone to a denial-of-service vulnerability.
Attackers can exploit this issue to crash the affected application, resulting in denial-of-service conditions. Due to the nature of this issue, code execution may be possible but this has not been confirmed.
VAR-E-201608-0509 | No CVE | Huawei eSpace IAD Information Disclosure | No EDB ID |
Huawei eSpace IAD suffers from an information disclosure vulnerability.
VAR-E-201607-0668 |
CVE-2016-7125 |
PHP 'ext/session/session.c' Remote Code Injection Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201609-0496 | No EDB ID |
PHP is prone to a vulnerability that lets attackers inject and execute arbitrary code.
Successful exploits may allow an attacker to inject and run arbitrary code or obtain sensitive information that may aid in further attacks. Failed exploit attempts may result in a denial-of-service condition.
VAR-E-201607-0102 | No CVE | Neoscreen Multiple Security Vulnerabilities | No EDB ID |
Neoscreen is prone to multiple security vulnerabilities.
An attacker may exploit these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, compromise the application, access or modify data or to bypass authentication mechanism; that may aid in further attacks.
Neoscreen 4.5 is vulnerable; other versions may also be affected.
VAR-E-201607-0716 | No CVE | Technicolor TC7200 Modem / Router Session Management / Fixed Password | No EDB ID |
The Technicolor TC7200 suffers from session management issues and also uses a fixed password for backup file encryption. Proof of concept code included.
VAR-E-201607-0413 |
CVE-2016-5787 |
GE Proficy HMI SCADA CIMPLICITY CVE-2016-5787 Local Privilege Escalation Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201607-0454 | No EDB ID |
GE Proficy HMI SCADA CIMPLICITY is prone to a local privilege escalation vulnerability.
An attacker can exploit this vulnerability to gain elevated privileges. This may aid in further attacks.
GE Proficy HMI SCADA CIMPLICITY 8.2 SIM 26 and prior are vulnerable.
VAR-E-201606-0744 | No CVE | Lenovo ThinkPad System Management Mode Local Privilege Escalation Vulnerability | No EDB ID |
Lenovo ThinkPad is prone to a local privilege escalation vulnerability.
A local attacker can leverage this issue to execute arbitrary code with administrative privileges in the context of the System Management Mode.
VAR-E-201606-0225 | No CVE | Lenovo ThinkPad - System Management Mode Arbitrary Code Execution - Windows local Exploit | EDB ID: 40040 |
Lenovo ThinkPad - System Management Mode Arbitrary Code Execution.. local exploit for Windows platform
VAR-E-201606-0458 |
CVE-2016-5829 |
Linux Kernel 'usbhid/hiddev.c' Local Heap Buffer Overflow Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201606-0329 | No EDB ID |
The Linux kernel is prone to a local heap-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Local attackers may exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely crash the kernel, denying service to legitimate users.
VAR-E-201605-0284 |
CVE-2010-5326 |
Multiple SAP Business Applications Incomplete Fix Remote Code Execution Vulnerability
Related entries in the VARIoT vulnerabilities database: VAR-201605-0004 | No EDB ID |
Multiple SAP Business applications running on SAP Java platforms are prone to a remote code-execution vulnerability.
An attacker may leverage this issue to execute arbitrary script code within the context of the affected application.
Note : This issue is the result of an incomplete fix for the issue described in 48925 (SAP Netweaver Invoker Servlet Remote Code Execution Vulnerability).
VAR-E-201605-0063 |
CVE-2015-6023 CVE-2015-6024 |
NetCommWireless HSPA 3G10WVE Wireless Router - Multiple Vulnerabilities - CGI webapps Exploit
Related entries in the VARIoT vulnerabilities database: VAR-201702-0400, VAR-201702-0312 | EDB ID: 39762 |
NetCommWireless HSPA 3G10WVE Wireless Router - Multiple Vulnerabilities. CVE-2015-6024CVE-2015-6023 . webapps exploit for CGI platform
VAR-E-201604-0137 | No CVE | Sony Playstation 4 (PS4) 1.76 - 'dlclose' Linux Kernel Loader - Hardware local Exploit | EDB ID: 44206 |
Sony Playstation 4 (PS4) 1.76 - 'dlclose' Linux Kernel Loader.. local exploit for Hardware platform