Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DB✓ VexDay Proof
OllyDbg 1.10 - Format String
CVE-2004-0733—localwindows10 ago 2004
Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly ex
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GNU Mailutils 0.6 - Mail Email Header Buffer Overflow
CVE-2005-1520—remotelinux10 ago 2004
Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions befo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GNU CFEngine 2.0.x/2.1 - AuthenticationDialogue Remote Heap Buffer Overrun (1)
CVE-2004-1701—doslinux09 ago 2004
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GNU CFEngine 2.0.x/2.1 - AuthenticationDialogue Remote Heap Buffer Overrun (2)
CVE-2004-1701—remotelinux09 ago 2004
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
xine 0.99.2 - Remote Stack Overflow
CVE-2004-1475—remotelinux09 ago 2004
Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1)
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RhinoSoft Serv-U FTP Server 3.x < 5.x - Local Privilege Escalation
CVE-2004-2532—localwindows08 ago 2004
Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users t
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PHP 4.3.7 - 'php-exec-dir' Patch Command Access Restriction Bypass
CVE-2004-2692—webappsphp08 ago 2004
The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass rest
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Pavuk Digest - Authentication Remote Buffer Overflow
CVE-2004-1437—remotelinux08 ago 2004
Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attacke
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Messenger (Linux) - Denial of Service (MS03-043)
CVE-2003-0717—doswindows08 ago 2004
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allow
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
CVSTrac - Arbitrary Code Execution
CVE-2004-1456—remotelinux06 ago 2004
filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BlackJumboDog FTP Server - Remote Buffer Overflow
CVE-2004-1439—remotewindows05 ago 2004
Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1)
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Ethereal 0.x - Multiple iSNS / SMB / SNMP Protocol Dissector Vulnerabilities
CVE-2004-0633—remotelinux05 ago 2004
The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abor
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle 9i - Multiple Vulnerabilities
CVE-2004-1364—remoteunix04 ago 2004
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Free Web Chat Initial Release - UserManager.java Null Pointer Denial of Service
CVE-2004-2646—dosmultiple04 ago 2004
The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (unca
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.26 - File Offset Pointer Handling Memory Disclosure
CVE-2004-0415—locallinux04 ago 2004
Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portio
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenFTPd 0.30.1 - message system Remote Shell
CVE-2004-2523—remotelinux04 ago 2004
Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows rem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eNdonesia 8.3 - Search Form Cross-Site Scripting
CVE-2004-2670—webappsphp04 ago 2004
Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitra
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - 'mshtml.dll' Remote Null Pointer Crash
CVE-2004-2434—doswindows04 ago 2004
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SoX - '.wav' Local Buffer Overflow
CVE-2004-0557—locallinux04 ago 2004
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allo
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Free Web Chat Initial Release - Connection Saturation Denial of Service
CVE-2004-2647—dosmultiple04 ago 2004
Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Acme thttpd 2.0.7 - Directory Traversal
CVE-2004-2628—remotewindows04 ago 2004
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
OpenFTPd 0.30.2 - Remote Overflow
CVE-2004-2523—remotelinux03 ago 2004
Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows rem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
IBM Tivoli Directory Server 3.2.2/4.1 - LDACGI Directory Traversal
CVE-2004-2526—remotewindows02 ago 2004
Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Citadel/UX - Remote Denial of Service (PoC)
CVE-2004-1705—doslinux02 ago 2004
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Webcam Corp Webcam Watchdog 4.0.1 - 'sresult.exe' Cross-Site Scripting
CVE-2004-2528—remotecgi02 ago 2004
Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Mozilla 1.x / Netscape 7.0/7.1 - SOAP Integer Overflow
CVE-2004-0722—doslinux02 ago 2004
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and po
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache - Arbitrary Long HTTP Headers Denial of Service
CVE-2004-0493—doslinux02 ago 2004
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memor
45RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SoX - Local Buffer Overflow
CVE-2004-0557—locallinux01 ago 2004
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allo
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP - Task Scheduler '.job' Universal (MS04-022)
CVE-2004-0212—localwindows31 jul 2004
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, al
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle9i Database - Default Library Directory Privilege Escalation
CVE-2004-1707—localunix30 jul 2004
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default pa
23RIESGO
abrir ↗
← anteriorpágina 517 / 636siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.