VARIoT IoT exploits database

Affected products: vendor, model and version
Type can be e.g: Remote Code Execution or Denial of Service
Look up free text in title and description

VAR-E-200311-0029 No CVE Fortigate Firewall 2.x - selector Admin Interface Cross-Site Scripting - Hardware remote Exploit EDB ID: 23379
Fortigate Firewall 2.x - selector Admin Interface Cross-Site Scripting. CVE-3296 . remote exploit for Hardware platform
VAR-E-200311-0030 No CVE Fortigate Firewall 2.x - listdel Admin Interface Cross-Site Scripting - Hardware remote Exploit EDB ID: 23378
Fortigate Firewall 2.x - listdel Admin Interface Cross-Site Scripting. CVE-3295 . remote exploit for Hardware platform
VAR-E-200311-0028 No CVE Fortigate Firewall 2.x - dlg Admin Interface Cross-Site Scripting - Hardware remote Exploit EDB ID: 23376
Fortigate Firewall 2.x - dlg Admin Interface Cross-Site Scripting. CVE-3289 . remote exploit for Hardware platform
VAR-E-200311-0031 No CVE Fortigate Firewall 2.x - Policy Admin Interface Cross-Site Scripting - Hardware remote Exploit EDB ID: 23377
Fortigate Firewall 2.x - Policy Admin Interface Cross-Site Scripting. CVE-3294 . remote exploit for Hardware platform
VAR-E-200310-0170 No CVE Novell PMAP.NLM Buffer Overrun Vulnerability No EDB ID
Novell has reported that the PMAP.NLM component of NetWare/ZenWorks is prone to a buffer overrun vulnerability. This condition could potentially be exploited to cause a denial of service or execute arbitrary code in the context of the software.
VAR-E-200309-0233 CVE-2003-0693
OpenSSH Buffer Mismanagement Vulnerabilities

Related entries in the VARIoT vulnerabilities database: VAR-200309-0035
No EDB ID
A buffer-mismanagement vulnerability has been reported in OpenSSH. This issue resides in the 'buffer.c' source file and may potentially be exploited to execute arbitrary code with the privileges of OpenSSH, but this has not been confirmed. The issue may cause a denial of service. This condition can reportedly be triggered by an overly large packet. There are also unconfirmed rumors of an exploit for this vulnerability circulating in the wild. OpenSSH has revised their advisory, pointing out a similar issue in the 'channels.c' source file and an additional issue in 'buffer.c'. Solar Designer has also reportedly pointed out additional instances of the problem that may also present vulnerabilities.
VAR-E-200308-0072 No CVE D-Link DI-704P - Long URL Denial of Service - Hardware dos Exploit EDB ID: 22991
D-Link DI-704P - Long URL Denial of Service.. dos exploit for Hardware platform
VAR-E-200308-0176 No CVE Cisco IOS 10/11/12 - UDP Echo Service Memory Disclosure - Hardware dos Exploit EDB ID: 22978
Cisco IOS 10/11/12 - UDP Echo Service Memory Disclosure. CVE-2352 . dos exploit for Hardware platform
VAR-E-200307-0238 No CVE Cisco IOS 2GB HTTP GET Buffer Overflow Vulnerability No EDB ID
The HTTP server on Cisco IOS devices is prone to a buffer overrun that can be triggered by sending 2GB of data. This may be exploited to execute arbitrary code on a vulnerable device.
VAR-E-200307-0193 CVE-2003-0567
Cisco IOS - using hping Remote Denial of Service - Hardware dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200308-0206
EDB ID: 62
Cisco IOS - using hping Remote Denial of Service. CVE-2325CVE-2003-0567 . dos exploit for Hardware platform
VAR-E-200307-0192 CVE-2003-0567
Cisco IOS - 'cisco-bug-44020.c' IPv4 Packet Denial of Service - Hardware dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200308-0206
EDB ID: 60
Cisco IOS - 'cisco-bug-44020.c' IPv4 Packet Denial of Service. CVE-2325CVE-2003-0567 . dos exploit for Hardware platform
VAR-E-200307-0191 CVE-2003-0567
Cisco IOS - IPv4 Packets Denial of Service - Hardware dos Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200308-0206
EDB ID: 59
Cisco IOS - IPv4 Packets Denial of Service. CVE-2325CVE-2003-0567 . dos exploit for Hardware platform
VAR-E-200307-0134 No CVE Cisco Catalyst Non-Standard TCP Flags Remote Denial Of Service Vulnerability No EDB ID
A problem with Cisco Catalyst switches has been reported in the handling of non-standard TCP packets. Because of this, an attacker may be able to deny legitimate user access to the switch.
VAR-E-200305-0078 No CVE D-Link DI-704P - Syslog.HTM Denial of Service - Hardware dos Exploit EDB ID: 22647
D-Link DI-704P - Syslog.HTM Denial of Service.. dos exploit for Hardware platform
VAR-E-200305-0058 No CVE Cisco IOS Service Assurance Agent Malformed Packet Denial Of Service Vulnerability No EDB ID
It has been reported that Cisco IOS is vulnerable to an issue in handling Service Assurance Agent (previously called Response Time Reporter, or RTR) packets. Because of this, a remote user may be able to cause the router to become unstable and crash.
VAR-E-200303-0114 No CVE Netgear ProSafe 1.x - VPN Firewall Web Interface Login Denial of Service - Hardware dos Exploit EDB ID: 22407
Netgear ProSafe 1.x - VPN Firewall Web Interface Login Denial of Service. CVE-55304 . dos exploit for Hardware platform
VAR-E-200303-0183 CVE-2003-0131
OpenSSL Bad Version Oracle Side Channel Attack Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200303-0118
No EDB ID
A problem with OpenSSL may leak sensitive information. A user could abuse the response of vulnerable servers to act as an oracle. By sending a large number of adaptive attacks, the possibility exists for a remote user to create a choice of ciphertext encrypted with the private key of the server.
VAR-E-200303-0184 CVE-2003-0147
OpenSSL Timing Attack RSA Private Key Information Disclosure Vulnerability

Related entries in the VARIoT vulnerabilities database: VAR-200303-0010
No EDB ID
A side-channel attack in the OpenSSL implementation has been published in a recent paper that may ultimately result in an active adversary gaining the RSA private key of a target server. The attack involves analysis of the timing of certain operations during client-server session key negotiation. Through this attack, it may be possible for a malicious client to discover the RSA private key of a server using the vulnerable software.
VAR-E-200303-0025 CVE-2003-0150
CVE-2016-5195
CVE-2016-6662
MySQL 3.23.x - 'mysqld' Local Privilege Escalation - Linux local Exploit

Related entries in the VARIoT vulnerabilities database: VAR-201611-0386
EDB ID: 22340
MySQL 3.23.x - 'mysqld' Local Privilege Escalation. CVE-2003-0150CVE-9909 . local exploit for Linux platform
VAR-E-200303-0035 CVE-2002-1337
Sendmail 8.12.x - Header Processing Buffer Overflow (2) - Unix remote Exploit

Related entries in the VARIoT vulnerabilities database: VAR-200303-0122
EDB ID: 22314
Sendmail 8.12.x - Header Processing Buffer Overflow (2). CVE-2002-1337CVE-4502 . remote exploit for Unix platform