Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

81,689cataloged exploits
38,075CVEs with public exploitation
24,695lab-tested
19,066 exploits
Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - Predictable TCP Initial Sequence Number
CVE-2000-0916—remotelinux27 Sep 1999
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate i
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0/4.0.1 - hhopen OLE Control Buffer Overflow
CVE-1999-1575—remotewindows27 Sep 1999
The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumb
35RISK
open ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - Predictable TCP Initial Sequence Number
CVE-2004-0641—remotelinux27 Sep 1999
Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP I
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0/4.0.1 - hhopen OLE Control Buffer Overflow
CVE-1999-1577—remotewindows27 Sep 1999
Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - Predictable TCP Initial Sequence Number
CVE-2001-0328—remotelinux27 Sep 1999
TCP implementations that use random increments for initial sequence numbers (ISN) can allow remote attackers to perform
28RISK
open ↗
Exploit-DB✓ VexDay Proof
Eicon Networks DIVA LAN ISDN Modem 1.0 Release 2.5/1.0/2.0 - Denial of Service
CVE-1999-1533—doshardware27 Sep 1999
Eicon Technology Diva LAN ISDN modem allows a remote attacker to cause a denial of service (hang) via a long password ar
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Mandriva Linux Mandrake 6.0 / Gnome Libs 1.0.8 - 'espeaker' Local Buffer Overflow
CVE-1999-1477—locallinux26 Sep 1999
Buffer overflow in GNOME libraries 1.0.8 allows local user to gain root access via a long --espeaker argument in program
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Knox Arkeia 4.0 Backup - Local Overflow
CVE-1999-1534—locallinux26 Sep 1999
Buffer overflow in (1) nlservd and (2) rnavc in Knox Software Arkeia backup product allows local users to obtain root ac
23RISK
open ↗
Exploit-DB✓ VexDay Proof
NCSA 1.3/1.4.x/1.5 / Apache HTTPd 0.8.11/0.8.14 - ScriptAlias Source Retrieval
CVE-1999-0236—remotemultiple25 Sep 1999
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
28RISK
open ↗
Exploit-DB✓ VexDay Proof
SuSE Linux 6.2 sscw - HOME Environment Variable Buffer Overflow
CVE-1999-0906—locallinux23 Sep 1999
Buffer overflow in sccw allows local users to gain root access via the HOME environmental variable.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Solaris 7.0 - Recursive mutex_enter Remote Panic (Denial of Service)
CVE-1999-0908—dossolaris23 Sep 1999
Denial of service in Solaris TCP streams driver via a malicious connection that causes the server to panic as a result o
23RISK
open ↗
Exploit-DB✓ VexDay Proof
FreeBSD 3.0/3.1/3.2 - 'vfs_cache' Denial of Service
CVE-1999-0912—dosfreebsd22 Sep 1999
FreeBSD VFS cache (vfs_cache) allows local users to cause a denial of service by opening a large number of files.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Solaris 2.6 - Profiling File Creation
CVE-1999-0786—localsolaris22 Sep 1999
The dynamic linker in Solaris allows a local user to create arbitrary files via the LD_PROFILE environmental variable an
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Martin Schulze Cfingerd 1.4.2 - GECOS Buffer Overflow
CVE-1999-0708—localfreebsd21 Sep 1999
Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
ProFTPd 1.2 pre6 - 'snprintf' Remote Root
CVE-2000-0824—remotelinux17 Sep 1999
The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/SP1/SP2/SP3/SP4/SP5 - RASMAN Privilege Escalation
CVE-1999-0886—localwindows17 Sep 1999
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Man
28RISK
open ↗
Exploit-DB✓ VexDay Proof
SSH Communications Security SSH 1.2.27 - Authentication Socket File Creation
CVE-1999-0787—locallinux17 Sep 1999
The SSH authentication agent follows symlinks via a UNIX domain socket.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Computalynx CMail 2.3 SP2/2.4 - SMTP Buffer Overflow
CVE-1999-1521—remotewindows13 Sep 1999
Computalynx CMail 2.4 and CMail 2.3 SP2 SMTP servers are vulnerable to a buffer overflow attack in the MAIL FROM command
23RISK
open ↗
Exploit-DB✓ VexDay Proof
DIGITAL UNIX 4.0 d/f / AIX 4.3.2 / CDE 2.1 / IRIX 6.5.14 / Solaris 7.0 / SunOS 4.1.4 - Local Buffer Overflow
CVE-1999-0693—locallinux13 Sep 1999
Buffer overflow in TT_SESSION environment variable in ToolTalk shared library allows local users to gain root privileges
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Netscape Enterprise Server 3.51/3.6 SP2 - Accept Buffer Overflow
CVE-1999-0751—remotemultiple13 Sep 1999
Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
FuseWare FuseMail 2.7 - POP Mail Buffer Overflow
CVE-1999-0759—remotewindows13 Sep 1999
Buffer overflow in FuseMAIL POP service via long USER and PASS commands.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
DIGITAL UNIX 4.0 d/e/f / AIX 4.3.2 / CDE 2.1 / IRIX 6.5.14 / Solaris 7.0 - Local Buffer Overflow
CVE-1999-0691—localmultiple13 Sep 1999
Buffer overflow in the AddSuLog function of the CDE dtaction utility allows local users to gain root privileges via a lo
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 / Netscape Communicator 4.0/4.5/4.6 - JavaScript STYLE
CVE-1999-0750—remotemultiple13 Sep 1999
Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the us
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Common Desktop Environment 2.1 20 / Solaris 7.0 - 'dtspcd' Local Privilege Escalation
CVE-1999-0689—localmultiple13 Sep 1999
The CDE dtspcd daemon allows local users to execute arbitrary commands via a symlink attack.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Solaris 7.0 /usr/bin/mail - '-m' Local Buffer Overflow
CVE-1999-1014—localsolaris12 Sep 1999
Buffer overflow in mail command in Solaris 2.7 and 2.7 allows local users to gain privileges via a long -m argument.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4.0.1/5 - Import/Export Favorites
CVE-1999-0702—remotewindows10 Sep 1999
Internet Explorer 5.0 and 5.01 allows remote attackers to modify or execute files via the Import/Export Favorites featur
28RISK
open ↗
Exploit-DB✓ VexDay Proof
FreeBSD 5.0 / NetBSD 1.4.2 / OpenBSD 2.7 - 'setsockopt()' Denial of Service
CVE-2000-0489—dosbsd05 Sep 1999
FreeBSD, NetBSD, and OpenBSD allow an attacker to cause a denial of service by creating a large number of socket pairs u
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Netscape Communicator 4.06/4.5/4.6/4.51/4.61 - EMBED Buffer Overflow
CVE-1999-0685—remotewindows02 Sep 1999
Buffer overflow in Netscape Communicator via EMBED tags in the pluginspage option.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
ISC INN 2.2 / RedHat Linux 6.0 - inews Buffer Overflow
CVE-1999-0705—localmultiple02 Sep 1999
Buffer overflow in INN inews program.
23RISK
open ↗
Exploit-DB✓ VexDay Proof
Martin Stover Mars NWE 0.99 - Local Buffer Overflow
CVE-1999-0774—locallinux31 Aug 1999
Buffer overflows in Mars NetWare Emulation (NWE, mars_nwe) package via long directory names.
23RISK
open ↗
← previouspage 623 / 636next →

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.