Packet Storm new exploits for April, 2009.
7121ded4c11f7b2540b672fabd936b53283b6675b48f18ee8deef905cb814757
PF in OpenBSD, NetBSD, and various other Unix variants suffer from a null pointer dereference vulnerability.
ea97857d82a2cb2bbd3b45b74c0233c3578d157ebfaccdebe90b3f664c1bca03
Mercury Audio Player version 1.21 local stack overflow proof of concept exploit that creates a malicious .m3u file.
985fb31fbc6651b9f8d278ad90a9f3810d597b5e6168f6b5aa323c89e6bfab21
Mercury Audio Player version 1.21 local SEH overwrite exploit that creates a malicious .pls file.
f39ac5fd4cb7aaf89c6b73c4144f477fe864ed338473b46298af8d659e055253
Mercury Audio Player version 1.21 local stack overflow exploit that creates a malicious .b4s file.
0dce3ae106d8558e3999f8dcafde55c71da0fee1090b15ded051c23b70ef9e43
Linux 2.6 kernel udev versions below 1.4.1 local privilege escalation exploit.
bd6992d84b7f36f4d79d12ce8930abcac49295702f6e9938849399ecc5ab82cd
Leap CMS version 0.1.4 suffers from cross site scripting, shell upload, and remote SQL injection vulnerabilities.
ea61aa70ca20ba665141ddbdeb9d384ab4141a837d0706f940762a57f70535c3
Leap CMS version 0.1.4 remote blind SQL injection exploit.
0c03dc8212ba5074ee9bf2e27277e893a5547eebcf97232ecf4b7662d46025e2
BaoFeng OnBeforeVideoDownload() remote buffer overflow exploit that leverages mps.dll.
e7bd45354adb5844438585aa09f35276b4af328a6517a1c1f94d3d0cf6a1dd58
S-CMS version 1.1 suffers from a local file inclusion vulnerability in plugin.php.
4a4a3b0b3843ec7861bccb3ebe429d18983fabf686e09d0c1475bee2cb218a33
Tiger DMS suffers from a remote SQL injection vulnerability that allows for authentication bypass.
e3be9fda1df89dba19e13af1895b32eead00a3b928a7639c0a9a64946a58749b
Zubrag Smart File Download version 1.3 suffers from an arbitrary file download vulnerability.
b4a68a7314a4a13323531468521e1d34fec1a11eaf11048054749b0f3fc75604
ProjectCMS version 1.0b suffers from a remote SQL injection vulnerability in index.php.
6b3590c0ce7aa31f3c3c8f0b97189e81616824240802c68ea371becce8e5f3f6
eLitius version 1.0 suffers from a remote SQL injection vulnerability in banner-details.php.
5ab4c494cd4102eee45eabc2762e27a093df413b6af21940d53411e0b4cb509a
mpegable Player version 2.12 local stack overflow proof of concept exploit that creates a malicious .yuv file.
d14ae85b3a52a1789b7852990c4e467e26ad305a767f031aaa8de0672ca2c7c3
Baby Web Server version 2.7.2.0 arbitrary file disclosure exploit.
6b17b31ff204c18d47dbfc2232e858107835c98b4ecb2a11da0ed60834001b6b
SEC Consult Security Advisory 20090429-0 - LevelOne AMG-2000 Wireless AP Management Gateway suffers from proxy bypass and plain text vulnerabilities.
21fedd3d58a60ec4be0f1b3d390a6efc6e4b55fd06209cf789610813125e1daf
Symantec Fax Viewer Control in WinFax Pro version 10.03 (DCCFAXVW.DLL) remote buffer overflow exploit.
2aed8b7e6e6ce96375af28dd2e4580c2567f748fbb45706ec2ce25127c08a6f9
Autodesk IDrop remote code execution Active-X related exploit.
7c9c190ffc784d425b6ced4e31666ab13e643782cb0241ab22e64961271029ed
Quick 'N Easy Web Server version 3.3.5 arbitrary file disclosure exploit.
28b096ec8d20eb70a76699f695c80411a360606cd936faada273201aaac98200
Google Chrome version 1.0.154.53 "throw exception" remote crash and denial of service exploit.
1fd4ca2e8e688fd3ee517eb4b6efdfa11c7e9969f30fa131e3935fb4e5fc6a4f
MIM:InfiniX version 1.2.003 suffers from multiple remote SQL injection vulnerabilities.
f43d1aad0582036b8773070a3abe01c14c13b177b3e4c21504ea040d4ea8c889
webSPELL versions 4.2.0d and below local file disclosure exploit.
133561498523b13aee4a2f2add63fb4c3b4b409b198a90c549f794852524b3a9
VisionLMS version 1.0 remote password changing exploit that leverages changePW.php.
355b4c9b088d211fb2b41e0d50a9c7539901f3429c0cfb67173f956a4cac54b8
Linux 2.6 kernel SCTP FWD memory corruption remote exploit.
7ff82e6eae31c3b23fa91ab46cc7407d4e0c84cdc92265c1fdb0e74131295a27