VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-201110-0076 No CVE Honeywell Tema Remote Installer - ActiveX Remote Code Execution (Metasploit) - Windows remote Exploit EDB ID: 24021
Honeywell Tema Remote Installer - ActiveX Remote Code Execution (Metasploit). CVE-76681 . remote exploit for Windows platform
VAR-E-201110-0144 No CVE atvise webMI2ADS 1.0 Directory Traversal / Denial Of Service No EDB ID
atvise webMI2ADS versions 1.0 and below suffer from directory traversal, NULL pointer, termination, and resource consumption vulnerabilities.
VAR-E-201110-0465 No CVE IRAI AUTOMGEN 8.0.0.7 Use-After-Free No EDB ID
IRAI AUTOMGEN versions 8.0.0.7 and below suffer from a use-after-free vulnerability.
VAR-E-201110-0003 CVE-2011-3368
CVE-2013-2465
CVE-2012-0507
CVE-2011-4885
CVE-2011-5035
Apache mod_proxy - Reverse Proxy Exposure - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201112-0123, VAR-201306-0242, VAR-201110-0291
EDB ID: 17969
Apache mod_proxy - Reverse Proxy Exposure. CVE-2011-3368CVE-76079 . remote exploit for Multiple platform
VAR-E-201110-0215 No CVE IRAI AUTOMGEN Use-After-Free Multiple Remote Code Execution Vulnerabilities No EDB ID
IRAI AUTOMGEN is prone to multiple remote code-execution vulnerabilities because it fails to properly validate user-supplied input. Attackers can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploits can trigger a denial-of-service condition. AUTOMGEN 8.0.0.7 is vulnerable; other versions may also be affected.
VAR-E-201110-0271 No CVE IRAI AUTOMGEN 8.0.0.7 - Use-After-Free - Windows dos Exploit EDB ID: 17964
IRAI AUTOMGEN 8.0.0.7 - Use-After-Free. CVE-76296 . dos exploit for Windows platform
VAR-E-201110-0085 CVE-2011-4871
OPC Systems.NET 4.00.0048 - Denial of Service - Windows dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201204-0097
EDB ID: 17965
OPC Systems.NET 4.00.0048 - Denial of Service. CVE-2011-4871CVE-76404 . dos exploit for Windows platform
VAR-E-201110-0219 CVE-2011-3296
Cisco Firewall Services Module Syslog Message Denial of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-201110-0254
No EDB ID
Cisco Firewall Services Module (FWSM) is prone to a denial-of-service vulnerability. An attacker can exploit this issue to cause the affected application to crash, denying service to legitimate users. This issue is being tracked by Cisco Bug ID CSCti83875.
VAR-E-201003-0011 CVE-2012-4681
CVE-2012-3539
CVE-2012-0547
CVE-2012-0053
CVE-2011-3368
Java 7 Applet - Remote Code Execution (Metasploit) - Java remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201208-0292, VAR-201208-0108, VAR-201110-0291, VAR-201201-0038
EDB ID: 20865
Java 7 Applet - Remote Code Execution (Metasploit). CVE-2012-4681CVE-84980CVE-2012-3539CVE-2012-0547CVE-84867 . remote exploit for Java platform
VAR-E-201003-0015 CVE-2013-2419
CVE-2013-2416
CVE-2012-0053
CVE-2011-3368
Java Web Start Launcher ActiveX Control - Memory Corruption - Windows dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038
EDB ID: 24966
Java Web Start Launcher ActiveX Control - Memory Corruption. CVE-2013-2419CVE-2013-2416CVE-92337 . dos exploit for Windows platform
VAR-E-201003-0012 CVE-2012-1533
CVE-2012-0053
CVE-2011-3368
Java - Web Start Double Quote Injection Remote Code Execution (Metasploit) - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201210-0458, VAR-201110-0291, VAR-201201-0038
EDB ID: 26123
Java - Web Start Double Quote Injection Remote Code Execution (Metasploit). CVE-2012-1533CVE-86348 . remote exploit for Multiple platform
VAR-E-201003-0013 CVE-2013-2465
CVE-2012-0053
CVE-2011-3368
Java - 'storeImageArray()' Invalid Array Indexing (Metasploit) - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201306-0242, VAR-201110-0291, VAR-201201-0038
EDB ID: 27705
Java - 'storeImageArray()' Invalid Array Indexing (Metasploit). CVE-2013-2465CVE-96269 . remote exploit for Multiple platform
VAR-E-201003-0020 CVE-2013-2460
CVE-2012-0053
CVE-2011-3368
Java Applet - ProviderSkeleton Insecure Invoke Method (Metasploit) - Multiple remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038
EDB ID: 26529
Java Applet - ProviderSkeleton Insecure Invoke Method (Metasploit). CVE-2013-2460CVE-94346 . remote exploit for Multiple platform
VAR-E-201110-0784 CVE-2012-0053
CVE-2011-3368
Oracle Java - 'storeImageArray()' Invalid Array Indexing - Windows remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038
EDB ID: 27526
Oracle Java - 'storeImageArray()' Invalid Array Indexing. CVE-96269 . remote exploit for Windows platform
VAR-E-201003-0018 CVE-2012-0551
CVE-2012-0053
CVE-2011-3368
Oracle GlassFish Server 3.1.1 (build 12) - Multiple Cross-Site Scripting Vulnerabilities - Windows webapps Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201205-0058, VAR-201110-0291, VAR-201201-0038
EDB ID: 18764
Oracle GlassFish Server 3.1.1 (build 12) - Multiple Cross-Site Scripting Vulnerabilities. CVE-2012-0551CVE-81250CVE-81237CVE-81236CVE-81235CVE-81234CVE-81233CVE-81232CVE-81231CVE-81230CVE-81229CVE-81228CVE-81227CVE-81226 . webapps exploit for Windows platform
VAR-E-201003-0023 CVE-2013-2470
CVE-2012-0053
CVE-2011-3368
Oracle Java lookUpByteBI - Heap Buffer Overflow - Windows dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201306-0147, VAR-201201-0038
EDB ID: 28050
Oracle Java lookUpByteBI - Heap Buffer Overflow. CVE-2013-2470CVE-94356 . dos exploit for Windows platform
VAR-E-201003-0025 CVE-2012-1723
CVE-2012-0053
CVE-2011-3368
Java Applet - Field Bytecode Verifier Cache Remote Code Execution (Metasploit) - Java remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201206-0059, VAR-201110-0291, VAR-201201-0038
EDB ID: 19717
Java Applet - Field Bytecode Verifier Cache Remote Code Execution (Metasploit). CVE-2012-1723CVE-82877 . remote exploit for Java platform
VAR-E-201003-0019 CVE-2013-1493
CVE-2012-0053
CVE-2011-3368
Java CMM - Remote Code Execution (Metasploit) - Windows remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038
EDB ID: 24904
Java CMM - Remote Code Execution (Metasploit). CVE-2013-1493CVE-90737 . remote exploit for Windows platform
VAR-E-201003-0024 CVE-2012-0053
CVE-2011-3368
Oracle Java - 'storeImageArray()' Invalid Array Indexing - Windows remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038
EDB ID: 27526
Oracle Java - 'storeImageArray()' Invalid Array Indexing. CVE-96269 . remote exploit for Windows platform
VAR-E-201110-0796 CVE-2011-4885
CVE-2012-0053
CVE-2011-3368
PHP Hash Table Collision - Denial of Service (PoC) - PHP dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201110-0291, VAR-201201-0038
EDB ID: 18305
PHP Hash Table Collision - Denial of Service (PoC). CVE-2011-4885CVE-78115 . dos exploit for PHP platform