hpqxml.dll version 2.0.0.133 from the HP Photo Digital Imaging software package has a flaw that allows for arbitrary file overwrite on the underlying system.
d5ed8c3f7dc685ae2d44fdc333686f1a4233c2473a12d3a6228b16977266b09b
QuickTicket version 1.2 suffers from a local file inclusion vulnerability in qti_checkname.php.
71544a547a68d6a05fbf7e16cb9e1f8f5a8727924b0b7b3cc17fb1621087b31a
QuickTalk forum version 1.3 suffers from local file inclusion vulnerabilities.
5068c4cd8d68ec79194cf3bcbbf8697e40574eeb0fa6c4127c8a3b865ccc8a07
Sony Network Camera SNC-P5 version 1.0 ActiveX viewer heap overflow proof of concept denial of service exploit.
2848e6b5ecb0750e5005ec474e44c950ef5b91decc2778a0e20de5d37482ca14
RealNetworks RealPlayer/Helix Player SMIL wallclock stack overflow proof of concept denial of service exploit.
68e14478e4f096f8efadeb0d94891a14ff8995292a98f99547bb534907b4ee37
152 byte Win32 tiny download and exec shellcode.
d853d553fc7f574925a19fb5152e8bdc2901115fffcf6c04f6b041fa3fb266d1
It has been more than a year since Michael Lynn first demonstrated a reliable code execution exploit on Cisco IOS at Black Hat 2005. Although his presentation received a lot of media coverage in the security community, very little is known about the attack and the technical details surrounding the IOS check_heaps() vulnerability. This paper is a result of research carried out by IRM to analyze and understand the check_heaps() attack and its impact on similar embedded devices.
40dd024bc2d874958a21e126057bd31b7ed7d0c86e440e3d7f7f5635a1c9819c