VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-200505-0073 CVE-2005-1543
Novell ZENworks 6.5 - Desktop/Server Management Overflow (Metasploit) - Windows remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200505-0878
EDB ID: 16815
Novell ZENworks 6.5 - Desktop/Server Management Overflow (Metasploit). CVE-2005-1543CVE-16698 . remote exploit for Windows platform
VAR-E-200504-0269 CVE-2005-1280
Ethereal 0.10.10 / tcpdump 3.9.1 - 'rsvp_print' Infinite Loop Denial of Service - Multiple dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200505-1240
EDB ID: 956
Ethereal 0.10.10 / tcpdump 3.9.1 - 'rsvp_print' Infinite Loop Denial of Service. CVE-15904CVE-2005-1280 . dos exploit for Multiple platform
VAR-E-200504-0243 CVE-2005-1228
GNU GZip Filename Directory Traversal Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200504-0292
No EDB ID
The gzip utility is prone to a directory-traversal vulnerability. The issue occurs when gunzip is invoked on a malicious archive using the '-N' option. An archive containing an absolute path for a filename that contains '/' characters can cause the file to be written using the absolute path contained in the filename. A remote attacker may leverage this issue using a malicious archive to corrupt arbitrary files with the privileges of the user that is running the vulnerable software.
VAR-E-200504-0005 CVE-2004-1060
CVE-2004-0790
CVE-2004-0791
CVE-2005-0065
CVE-2005-0066
CVE-2005-0068
CVE-2005-0067
Multiple Vendor ICMP Implementation - Malformed Path MTU Denial of Service - Multiple dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200505-0928, VAR-200504-0003, VAR-200504-0002, VAR-200412-1124, VAR-200412-1123, VAR-200412-1122, VAR-200404-0081
EDB ID: 25388
Multiple Vendor ICMP Implementation - Malformed Path MTU Denial of Service. CVE-2004-1060CVE-15619 . dos exploit for Multiple platform
VAR-E-200504-0002 CVE-2004-0790
CVE-2004-0791
CVE-2004-1060
CVE-2005-0065
CVE-2005-0066
CVE-2005-0068
CVE-2005-0067
Multiple Vendor ICMP Message Handling - Denial of Service - Multiple dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200505-0928, VAR-200504-0003, VAR-200504-0002, VAR-200412-1124, VAR-200412-1123, VAR-200412-1122, VAR-200404-0081
EDB ID: 25389
Multiple Vendor ICMP Message Handling - Denial of Service. CVE-2004-0790CVE-15457 . dos exploit for Multiple platform
VAR-E-200504-0006 CVE-2004-0791
CVE-2004-0790
CVE-2004-1060
CVE-2005-0065
CVE-2005-0066
CVE-2005-0068
CVE-2005-0067
Multiple Vendor ICMP Implementation - Spoofed Source Quench Packet Denial of Service - Multiple dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200505-0928, VAR-200504-0003, VAR-200504-0002, VAR-200412-1124, VAR-200412-1123, VAR-200412-1122, VAR-200404-0081
EDB ID: 25387
Multiple Vendor ICMP Implementation - Spoofed Source Quench Packet Denial of Service. CVE-2004-0791CVE-15618 . dos exploit for Multiple platform
VAR-E-200504-0453 CVE-2005-1057
Cisco IOS Easy VPN Server XAUTH Authentication Bypass Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200505-0997
No EDB ID
Cisco IOS Easy VPN Server is reported prone to an authentication bypass vulnerability. This issue can allow remote attackers to bypass Extended Authentication (XAUTH) and gain unauthorized access to resources. An unauthorized attacker may send certain malformed UDP packets to UDP port 500 to complete XAUTH authentication and gain unauthorized access to network resources.
VAR-E-200504-0253 CVE-2005-1058
Cisco IOS Unauthorized Security Association Establishment Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200505-0998
No EDB ID
Cisco IOS is prone to an issue related to XAUTH and ISAKMP profiles that may allow a malicious VPN client to gain unauthorized access to a VPN. The vulnerability occurs in a case where attributes in an ISAKMP profile that have been assigned to remote peer are not processed. This will present a window of opportunity for the remote client to initiate Phase 2 IKE negotiation and cause an unauthorized IPSec SA (Security Association) to be established. It is noted that the vulnerability only affects those ISAKMP profiles that are matched by pre-configured certificate maps.
VAR-E-200503-0133 CVE-2005-0943
Cisco VPN 3000 Concentrator Remote Denial of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200503-0138
No EDB ID
Cisco VPN 3000 Concentrator products are reported prone to a remote denial of service vulnerability. A remote unauthenticated attacker may trigger this vulnerability to cause an affected device to reload or drop connections. Specifically, an attacker can target the HTTPS service running on a vulnerable device to trigger this vulnerability. Cisco VPN 3000 Concentrator products running software version 4.1.7.A and prior are affected by this issue.
VAR-E-200503-0240 CVE-2005-0468
Multiple Vendor Telnet Client - Env_opt_add Heap Buffer Overflow - Linux dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200505-0162
EDB ID: 25303
Multiple Vendor Telnet Client - Env_opt_add Heap Buffer Overflow. CVE-2005-0468CVE-15093 . dos exploit for Linux platform
VAR-E-200503-0001 CVE-2005-0688
CVE-2005-1649
Microsoft Windows XP/2003 - Remote Denial of Service - Windows dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200505-0723, VAR-200503-0010
EDB ID: 861
Microsoft Windows XP/2003 - Remote Denial of Service. CVE-14578CVE-2005-1649CVE-2005-0688 . dos exploit for Windows platform
VAR-E-200502-0248 CVE-2005-0490
cURL / libcURL Kerberos Authentication Buffer Overflow Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200505-0198
No EDB ID
It has been reported that cURL and libcURL are vulnerable to a remotely exploitable stack-based buffer overflow vulnerability. The cURL and libcURL Kerberos authentication code fails to ensure that a buffer overflow cannot occur when server response data is decoded. The overflow occurs in the stack region, and remote code execution is possible if the saved instruction pointer is overwritten with a pointer to embedded instructions.
VAR-E-200501-0112 CVE-2005-0195
Cisco IOS IPv6 Processing Remote Denial Of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200505-1154
No EDB ID
A remote denial of service vulnerability affects the IPv6 processing functionality of Cisco IOS. This issue is due to a failure of the affected operating system to properly handle specially crafted network data. It is possible for an attacker to produce a sustained denial of service condition against an affected device by continually sending the malicious network data. An attacker may leverage this issue to cause an affected device to reload, denying service to legitimate users.
VAR-E-200501-0306 CVE-2005-0196
Cisco IOS Border Gateway Protocol Processing Remote Denial Of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200505-1148
No EDB ID
A remote denial of service vulnerability affects the Border Gateway Protocol (BGP) processing functionality of Cisco IOS. This issue is due to a failure of the application to handle malformed network data. An attacker may leverage this issue to trigger a denial of service condition in the affected device. A persistent denial of service attack can be triggered as well.
VAR-E-200501-0178 CVE-2005-0197
Cisco IOS Multi Protocol Label Switching Remote Denial Of Service Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200505-1149
No EDB ID
Cisco IOS based routers that are configured with support for Multi Protocol Label Switching (MPLS) are reported prone to a remote denial of service vulnerability. It is reported that the vulnerability presents itself when an affected router handles an unspecified malicious packet on a MPLS disabled interface. A remote attacker that resides on the same network segment as the vulnerable router may exploit this vulnerability continuously to effectively deny network-based services to legitimate users.
VAR-E-200501-0251 No CVE Cisco IOS Skinny Call Control Protocol Handler Remote Denial Of Service Vulnerability No EDB ID
Cisco IOS when configured for Cisco IOS Telephony Service (ITS), Cisco CallManager Express (CME), or Survivable Remote Site Telephony (SRST) services is reported prone to a remote denial of service vulnerability. The issue is reported to exist in the Skinny Call Control Protocol (SCCP) handler. A remote attacker may exploit this vulnerability continuously to effectively deny network-based services to legitimate users.
VAR-E-200412-0151 CVE-2004-2761
MD5 - Message Digest Algorithm Hash Collision - Multiple dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200901-0466
EDB ID: 24807
MD5 - Message Digest Algorithm Hash Collision. CVE-2004-2761CVE-45127 . dos exploit for Multiple platform
VAR-E-200411-0103 CVE-2004-1540
ZYXEL 3 Prestige Router - HTTP Remote Administration Configuration Reset - Hardware remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200412-0994
EDB ID: 24760
ZYXEL 3 Prestige Router - HTTP Remote Administration Configuration Reset. CVE-2004-1540CVE-12108 . remote exploit for Hardware platform
VAR-E-200411-0242 No CVE 3Com OfficeConnect ADSL Wireless 11g Firewall Router Remote Denial Of Service Vulnerability No EDB ID
A remote denial of service vulnerability affects the 3Com OfficeConnect ADSL Wireless 11g Firewall Router. This issue is due to a failure of the application to handle anomalous network traffic. An attacker may leverage this issue to cause the affected router to crash, denying service to legitimate users.
VAR-E-200411-0206 No CVE Allied Telesyn TFTP Daemon Multiple Remote Vulnerabilities No EDB ID
The Allied Telesyn TFTP service is reported to be prone to multiple vulnerabilities. The following specific issues are reported: 1. Allied Telesyn TFTP Server is reported susceptible to a directory-traversal vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input data. This vulnerability allows remote attackers to retrieve or overwrite the contents of arbitrary potentially sensitive files located on the serving appliance with the privileges of the TFTP server process. 2. Allied Telesyn TFTP Server is reported prone to a remote buffer-overflow vulnerability. This vulnerability may be exploited by a remote attacker to crash the affected service. NOTE (November 17, 2010): This vendor may now be known as Allied Telesis.