VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-201205-0344 CVE-2012-6050
Mikrotik Router - Denial of Service - Hardware dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201211-0306
EDB ID: 18817
Mikrotik Router - Denial of Service. CVE-81805CVE-2012-6050 . dos exploit for Hardware platform
VAR-E-201204-0615 CVE-2012-4867
vTiger CRM 5.1.0 - Local File Inclusion - PHP webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201209-0439
EDB ID: 18770
vTiger CRM 5.1.0 - Local File Inclusion. CVE-80552CVE-2012-4867 . webapps exploit for PHP platform
VAR-E-201204-0001 CVE-2012-2110
CVE-2012-2131
CVE-2015-7855
CVE-2016-6415
CVE-2014-2109
CVE-2014-2111
CVE-2014-2108
CVE-2014-0224
CVE-2014-0195
CVE-2014-2106
CVE-2015-0643
CVE-2015-0642
CVE-2013-0166
CVE-2014-3354
OpenSSL - ASN1 BIO Memory Corruption - Multiple dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201503-0183, VAR-201503-0184, VAR-201403-0475, VAR-201403-0477, VAR-201403-0478, VAR-201403-0479, VAR-201409-0404, VAR-201609-0325, VAR-201406-0445, VAR-201708-0038, VAR-201406-0137
EDB ID: 18756
OpenSSL - ASN1 BIO Memory Corruption. CVE-2012-2131CVE-81223CVE-2012-2110 . dos exploit for Multiple platform
VAR-E-201204-0129 CVE-2012-4329
CVE-2012-4330
CVE-2012-4334
CVE-2012-4333
CVE-2012-4335
Samsung NET-i ware 1.37 - Multiple Vulnerabilities - Windows dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201208-0213, VAR-201208-0214
EDB ID: 18765
Samsung NET-i ware 1.37 - Multiple Vulnerabilities. CVE-81452CVE-81222CVE-2012-4335CVE-2012-4334CVE-2012-4333CVE-81221CVE-2012-4330CVE-2012-4329 . dos exploit for Windows platform
VAR-E-201204-0003 CVE-2015-7855
CVE-2016-6415
CVE-2014-2109
CVE-2014-2111
CVE-2014-2108
CVE-2014-0224
CVE-2014-0195
CVE-2014-2106
CVE-2015-0643
CVE-2015-0642
CVE-2013-0166
CVE-2012-2110
CVE-2014-3354
NTP 4.2.8p3 - Denial of Service - Linux dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201503-0183, VAR-201503-0184, VAR-201403-0475, VAR-201403-0477, VAR-201403-0478, VAR-201403-0479, VAR-201409-0404, VAR-201609-0325, VAR-201406-0445, VAR-201708-0038, VAR-201406-0137
EDB ID: 40840
NTP 4.2.8p3 - Denial of Service. CVE-2015-7855 . dos exploit for Linux platform
VAR-E-201204-0002 CVE-2016-6415
CVE-2015-7855
CVE-2014-2109
CVE-2014-2111
CVE-2014-2108
CVE-2014-0224
CVE-2014-0195
CVE-2014-2106
CVE-2015-0643
CVE-2015-0642
CVE-2013-0166
CVE-2012-2110
CVE-2014-3354
Cisco IOS 12.2 < 12.4 / 15.0 < 15.6 - Security Association Negotiation Request Device Memory - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201503-0183, VAR-201503-0184, VAR-201403-0475, VAR-201403-0477, VAR-201403-0478, VAR-201403-0479, VAR-201409-0404, VAR-201609-0325, VAR-201406-0445, VAR-201708-0038, VAR-201406-0137
EDB ID: 43383
Cisco IOS 12.2 < 12.4 / 15.0 < 15.6 - Security Association Negotiation Request Device Memory. CVE-2016-6415 . remote exploit for Hardware platform
VAR-E-201204-0128 CVE-2012-4329
CVE-2012-4330
Samsung D6000 TV - Multiple Vulnerabilities - Hardware dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201208-0213, VAR-201208-0214
EDB ID: 18751
Samsung D6000 TV - Multiple Vulnerabilities. CVE-81222CVE-81221CVE-2012-4330CVE-2012-4329 . dos exploit for Hardware platform
VAR-E-201204-0283 CVE-2012-1182
Samba 3.4.16/3.5.14/3.6.4 - SetInformationPolicy AuditEventsInfo Heap Overflow (Metasploit) - Linux remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201204-0112
EDB ID: 21850
Samba 3.4.16/3.5.14/3.6.4 - SetInformationPolicy AuditEventsInfo Heap Overflow (Metasploit). CVE-2012-1182CVE-81303 . remote exploit for Linux platform
VAR-E-201204-0659 No CVE Sony Bravia KDL-32CX525 - 'hping' Remote Denial of Service - Multiple dos Exploit EDB ID: 37061
Sony Bravia KDL-32CX525 - 'hping' Remote Denial of Service.. dos exploit for Multiple platform
VAR-E-201204-0164 CVE-2012-0226
CVE-2012-0228
CVE-2012-0225
Invensys Wonderware Information Server Multiple Security Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-201204-0145, VAR-201204-0175, VAR-201204-0176
No EDB ID
Invensys Wonderware Information Server is prone to multiple security vulnerabilities, including: 1. A cross-site scripting vulnerability 2. A SQL-injection vulnerability 3. A security-bypass vulnerability Attackers can leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of an affected site, steal cookie-based authentication credentials, perform unauthorized actions, obtain sensitive information, redirect a user to a potentially malicious site, cause a denial-of-service condition and compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. Other attacks are also possible.
VAR-E-201203-1152 CVE-2012-0507
CVE-2013-2465
Java - AtomicReferenceArray Type Violation (Metasploit) - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201306-0242
EDB ID: 18679
Java - AtomicReferenceArray Type Violation (Metasploit). CVE-2012-0507CVE-80724 . remote exploit for Multiple platform
VAR-E-201003-0016 CVE-2012-0507
CVE-2013-2465
Java - AtomicReferenceArray Type Violation (Metasploit) - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201306-0242
EDB ID: 18679
Java - AtomicReferenceArray Type Violation (Metasploit). CVE-2012-0507CVE-80724 . remote exploit for Multiple platform
VAR-E-201203-0747 CVE-2012-0383
Cisco IOS NAT Functionality SIP Denial of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201203-0210
No EDB ID
Cisco IOS is prone to a remote denial-of-service vulnerability. Successful exploits may allow an attacker to cause an affected device to consume excessive amounts of memory, resulting in a denial-of-service condition. This issue is being tracked by Cisco Bug ID CSCti35326.
VAR-E-201203-0308 CVE-2012-0381
Cisco Internet Key Exchange Denial of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201203-0211
No EDB ID
Cisco is prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to cause an affected device to reload, denying service to legitimate users. The following products using Internet Key Exchange (IKE) are vulnerable: LAN-to-LAN VPN. Remote access VPN (excluding SSLVPN). Dynamic Multipoint VPN (DMVPN). Group Domain of Interpretation (GDOI). This issue is being tracked by Cisco Bug ID CSCts38429.
VAR-E-201203-0109 CVE-2012-4876
TRENDnet SecurView TV-IP121WN Wireless Internet Camera - UltraMJCam ActiveX Control OpenFileDlg WideCharToMultiByte Remote Stack Buffer Overflow - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201209-0448
EDB ID: 18675
TRENDnet SecurView TV-IP121WN Wireless Internet Camera - UltraMJCam ActiveX Control OpenFileDlg WideCharToMultiByte Remote Stack Buffer Overflow. CVE-80661CVE-2012-4876 . remote exploit for Hardware platform
VAR-E-201203-0003 CVE-2012-0382
Cisco IOS Multicast Source Discovery Protocol Remote Denial of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201203-0209
No EDB ID
Cisco IOS is prone to a remote denial-of-service vulnerability. An attacker can exploit this issue to cause an affected device to reload, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCtr28857.
VAR-E-201203-1056 CVE-2012-1315
CVE-2012-0387
CVE-2012-1310
CVE-2012-0388
Cisco IOS Zone-Based Firewall Multiple Denial of Service Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-201203-0328, VAR-201203-0332, VAR-201203-0231, VAR-201203-0230
No EDB ID
Cisco IOS is prone to multiple remote denial-of-service vulnerabilities. An attacker can exploit these issues to cause an affected device to reload, denying service to legitimate users.
VAR-E-201203-0128 CVE-2012-5306
D-Link DCS-5605 Network Surveillance - ActiveX Control 'DcsCliCtrl.dll' lstrcpyW Remote Buffer Overflow - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201210-0439
EDB ID: 18673
D-Link DCS-5605 Network Surveillance - ActiveX Control 'DcsCliCtrl.dll' lstrcpyW Remote Buffer Overflow. CVE-80663CVE-2012-5306 . remote exploit for Hardware platform
VAR-E-201203-0108 CVE-2012-4876
TRENDnet SecurView Internet Camera - UltraMJCam OpenFileDlg Buffer Overflow (Metasploit) - Windows remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201209-0448
EDB ID: 18709
TRENDnet SecurView Internet Camera - UltraMJCam OpenFileDlg Buffer Overflow (Metasploit). CVE-80661CVE-2012-4876 . remote exploit for Windows platform
VAR-E-201203-0958 CVE-2012-1311
Cisco IOS RSVP Feature Remote Denial of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201203-0329
No EDB ID
Cisco IOS is prone to a remote denial-of-service vulnerability. Successful exploits will result in a denial-of-service condition. This issue is being tracked by Cisco Bug ID CSCts80643.