VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-200708-0103 CVE-2007-4318
CVE-2007-4317
CVE-2007-4319
ZYXEL ZyWALL 2 3.62 - '/Forms/General_1?sysSystemName' Cross-Site Scripting - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200708-0020, VAR-200708-0019, VAR-200708-0021
EDB ID: 30485
ZYXEL ZyWALL 2 3.62 - '/Forms/General_1?sysSystemName' Cross-Site Scripting. CVE-2007-4318CVE-38721 . remote exploit for Hardware platform
VAR-E-200708-0390 CVE-2007-4286
Cisco IOS Next Hop Resolution Protocol (NHRP) - Denial of Service - Windows dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200708-0166
EDB ID: 4272
Cisco IOS Next Hop Resolution Protocol (NHRP) - Denial of Service. CVE-36692CVE-2007-4286 . dos exploit for Windows platform
VAR-E-200708-0318 CVE-2007-4292
CVE-2007-4295
CVE-2007-4294
CVE-2007-4291
CVE-2007-4293
Cisco IOS and Unified Communications Manager Multiple Voice Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-200708-0171, VAR-200708-0172, VAR-200708-0173, VAR-200708-0174, VAR-200708-0175
No EDB ID
Cisco IOS and Unified Communications Manager are prone to multiple denial-of-service and code-execution vulnerabilities. These issues pertain to the following protocols or features: Session Initiation Protocol (SIP) Media Gateway Control Protocol (MGCP) Signaling protocols H.323, H.254 Real-time Transport Protocol (RTP) Facsimile reception A remote attacker can exploit these issues to execute arbitrary code or cause denial-of-service conditions.
VAR-E-200707-0623 CVE-2007-4011
CVE-2007-4012
Cisco Wireless LAN Control ARP Storm Multiple Denial Of Service Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-200707-0187, VAR-200707-0188
No EDB ID
Cisco Wireless LAN Controller (WLC) is prone to multiple denial-of-service vulnerabilities. An attacker can exploit these issues to crash the device, denying service to legitimate users. These issues affect Cisco Wireless LAN Control 3.2, 4.0, and 4.1; other versions may also be affected.
VAR-E-200707-0132 CVE-2007-3605
CVE-2007-3607
CVE-2007-3608
EnjoySAP SAP GUI - ActiveX Control Buffer Overflow (Metasploit) - Windows remote Exploit EDB ID: 16498
EnjoySAP SAP GUI - ActiveX Control Buffer Overflow (Metasploit). CVE-2007-3605CVE-37690 . remote exploit for Windows platform
VAR-E-200706-0107 CVE-2007-3334
CVE-2007-3338
CVE-2007-3337
CVE-2007-3336
Ingress Database Server 2.6 - Multiple Remote Vulnerabilities - Windows dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200706-0398, VAR-200706-0399, VAR-200706-0397, VAR-200706-0395
EDB ID: 30224
Ingress Database Server 2.6 - Multiple Remote Vulnerabilities. CVE-2007-3334CVE-37487 . dos exploit for Windows platform
VAR-E-200705-0518 CVE-2007-3304
Apache HTTP Server Worker Process Multiple Denial of Service Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-200705-0681
No EDB ID
Apache is prone to multiple denial-of-service vulnerabilities. An attacker with the ability to execute arbitrary server-side script-code can exploit these issues to stop arbitrary services on the affected computer in the context of the master webserver process; other attacks may also be possible.
VAR-E-200705-0231 No CVE Sony Playstation 3 Internet Browser Multiple Denial Of Service Vulnerabilities No EDB ID
Sony Playstation 3 is prone to multiple denial-of-service vulnerabilities because its browser fails to adequately handle user-supplied data. An attacker can exploit this issue by exhausting memory resources to cause the browser to become unresponsive or to crash the device.
VAR-E-200705-0522 CVE-2006-3894
RSA BSAFE Library Remote ASN.1 Denial of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200705-0570
No EDB ID
The RSA BSAFE library is prone to a denial-of-service vulnerability because it fails to properly handle malformed ASN.1 data. Exploiting this vulnerability allows attackers to crash applications that use the affected library. The specific impact of this vulnerability depends on the nature of the applications. Local and remote attacks may be possible. Depending on the nature of vulnerable applications, attackers may be able to exploit this issue without authentication. These versions are vulnerable: RSA BSAFE Crypto-C prior to 6.3.1 Cert-C prior to 2.8 The vendor tracks this issue by RSA Bug ID 46337. Cisco tracks this issue as Bug IDs: Cisco IOS: CSCsd85587 Cisco IOS XR: CSCsg41084 Cisco PIX and ASA Security Appliances: CSCse91999 Cisco Firewall Services Module (FWSM): CSCsi97695 Cisco Unified CallManager: CSCsg44348
VAR-E-200705-0357 CVE-2007-2586
CVE-2007-2587
Cisco IOS 12.3(18) (FTP Server) - Remote (Attached to GDB) - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200705-0283, VAR-200705-0284
EDB ID: 6155
Cisco IOS 12.3(18) (FTP Server) - Remote (Attached to GDB). CVE-2007-2586 . remote exploit for Hardware platform
VAR-E-200704-0339 CVE-2007-2036
CVE-2007-2039
CVE-2007-2038
CVE-2007-2041
CVE-2007-2037
CVE-2007-2040
Cisco Wireless Lan Controller Multiple Remote Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-200704-0020, VAR-200704-0021, VAR-200704-0022, VAR-200704-0023, VAR-200704-0024, VAR-200704-0025
No EDB ID
Cisco Wireless LAN Controller (WLC) is prone to multiple remote vulnerabilities, including an unauthorized-access vulnerability, an information-disclosure vulnerability, and a vulnerability that prevents the WLAN's ACLs from being installed. An attacker can exploit these issues to completely compromise the affected device, cause a denial-of-service condition, obtain potentially sensitive information, and gain unauthorized access to the affected device.
VAR-E-200704-0606 No CVE Miniwebsvr Server Directory Traversal Vulnerability No EDB ID
Miniwebsvr is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the affected application. Information obtained may aid in further attacks. Note that the attacker can traverse to only one directory above the current working directory of the webserver application. Miniwebsvr 0.0.7 is vulnerable to this issue; other versions may also be affected. UPDATE (March 4, 2008): Miniwebsvr 0.0.9a is also reported vulnerable.
VAR-E-200704-0607 CVE-2007-0734
CVE-2007-0732
CVE-2007-0744
CVE-2007-0737
CVE-2007-0729
CVE-2007-0735
CVE-2007-0746
CVE-2007-0743
CVE-2007-0736
CVE-2007-0747
CVE-2007-0741
CVE-2007-0739
CVE-2007-0725
CVE-2007-0738
CVE-2007-0742
Apple Mac OS X 2007-004 Multiple Security Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-200704-0214, VAR-200704-0227, VAR-200704-0223, VAR-200704-0224, VAR-200704-0226, VAR-200704-0225, VAR-200704-0222, VAR-200704-0219, VAR-200704-0220, VAR-200704-0221, VAR-200704-0218, VAR-200704-0216, VAR-200704-0217, VAR-200704-0215, VAR-200704-0213
No EDB ID
Apple Mac OS X is prone to multiple security vulnerabilities. These issues affect Mac OS X and various applications, including AFP Client, AirPortDriver module, CoreServices, Libinfo, Login Window, Natd, SMB, System Configuration, URLMount, VideoConference framework, WebDAV, and WebFoundation. Attackers may exploit these issues to execute arbitrary code, trigger denial-of-service conditions, escalate privileges, overwrite files, and access potentially sensitive information. Both local and remote vulnerabilities are present. Apple Mac OS X 10.4.9 and prior versions are vulnerable to these issues.
VAR-E-200703-0008 CVE-2008-2938
CVE-2006-7196
CVE-2007-0450
CVE-2007-2449
CVE-2007-1355
CVE-2007-3386
CVE-2006-3835
CVE-2007-3382
CVE-2007-3385
CVE-2007-4724
Apache Tomcat <= 6.0.18 UTF8 Directory Traversal Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200808-0154, VAR-200703-0007
EDB ID: 30563
Apache Tomcat 5.5.15 - cal2.jsp Cross-Site Scripting. CVE-2006-7196CVE-34888 . webapps exploit for JSP platform
VAR-E-200703-0006 CVE-2008-2938
CVE-2007-3382
CVE-2007-0450
CVE-2007-2449
CVE-2007-1355
CVE-2007-3386
CVE-2006-3835
CVE-2007-3385
CVE-2007-4724
CVE-2006-7196
Apache Tomcat <= 6.0.18 UTF8 Directory Traversal Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200808-0154, VAR-200703-0007
EDB ID: 30496
Apache Tomcat 6.0.13 - Insecure Cookie Handling Quote Delimiter Session ID Disclosure. CVE-2007-3382CVE-37070 . remote exploit for Multiple platform
VAR-E-200703-0005 CVE-2008-2938
CVE-2007-0450
CVE-2007-2449
CVE-2007-1355
CVE-2007-3386
CVE-2006-3835
CVE-2007-3382
CVE-2007-3385
CVE-2007-4724
CVE-2006-7196
Apache Tomcat <= 6.0.18 UTF8 Directory Traversal Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200808-0154, VAR-200703-0007
EDB ID: 14489
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal. CVE-2008-2938 . remote exploit for Unix platform
VAR-E-200703-0007 CVE-2007-0450
CVE-2008-2938
CVE-2007-2449
CVE-2007-1355
CVE-2007-3386
CVE-2006-3835
CVE-2007-3382
CVE-2007-3385
CVE-2007-4724
CVE-2006-7196
Apache Tomcat <= 6.0.18 UTF8 Directory Traversal Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200808-0154, VAR-200703-0007
EDB ID: 29739
Apache Tomcat 5.x/6.0.x - Directory Traversal. CVE-2007-0450CVE-34769 . remote exploit for Linux platform
VAR-E-200703-0002 CVE-2007-2449
CVE-2008-2938
CVE-2007-0450
CVE-2007-1355
CVE-2007-3386
CVE-2006-3835
CVE-2007-3382
CVE-2007-3385
CVE-2007-4724
CVE-2006-7196
Apache Tomcat <= 6.0.18 UTF8 Directory Traversal Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200808-0154, VAR-200703-0007
EDB ID: 30189
Apache Tomcat 6.0.13 - JSP Example Web Applications Cross-Site Scripting. CVE-2007-2449CVE-36080 . webapps exploit for JSP platform
VAR-E-200703-0001 CVE-2008-2938
CVE-2007-0450
CVE-2007-2449
CVE-2007-1355
CVE-2007-3386
CVE-2006-3835
CVE-2007-3382
CVE-2007-3385
CVE-2007-4724
CVE-2006-7196
Apache Tomcat <= 6.0.18 UTF8 Directory Traversal Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200808-0154, VAR-200703-0007
EDB ID: 6229
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal (PoC). CVE-47464CVE-2008-2938 . remote exploit for Multiple platform
VAR-E-200703-0003 CVE-2007-3386
CVE-2008-2938
CVE-2007-0450
CVE-2007-2449
CVE-2007-1355
CVE-2006-3835
CVE-2007-3382
CVE-2007-3385
CVE-2007-4724
CVE-2006-7196
Apache Tomcat <= 6.0.18 UTF8 Directory Traversal Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200808-0154, VAR-200703-0007
EDB ID: 30495
Apache Tomcat 6.0.13 - Host Manager Servlet Cross-Site Scripting. CVE-2007-3386CVE-36417 . remote exploit for Multiple platform