Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DB✓ VexDay Proof
Solaris Runtime Linker (SPARC) - 'ld.so.1' Local Buffer Overflow
CVE-2003-0609—localsolaris27 oct 2003
Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root pri
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Musicqueue 1.2 - SIGSEGV Signal Handler Insecure File Creation
CVE-2003-1139—locallinux27 oct 2003
Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Wireless Tools 26 (IWConfig) - ARGV Local Command Line Buffer Overflow (1)
CVE-2003-0947—locallinux27 oct 2003
Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environm
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Chi Kien Uong Guestbook 1.51 - Cross-Site Scripting
CVE-2003-1136—webappsphp27 oct 2003
Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
RedHat Apache 2.0.40 - Directory Index Default Configuration Error
CVE-2003-1138—remotelinux27 oct 2003
The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Yahoo! Messenger 5.6 - File Transfer Buffer Overrun
CVE-2003-1135—doswindows27 oct 2003
Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send req
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Symantec Norton Internet Security 2003 6.0.4.34 - Error Message Cross-Site Scripting
CVE-2003-1149—remotecgi27 oct 2003
Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to i
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Microsystems Java Virtual Machine 1.x - Security Manager Denial of Service
CVE-2003-1134—dosmultiple26 oct 2003
Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the Cl
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - Messenger Service Buffer Overrun (MS03-043)
CVE-2003-0717—remotewindows25 oct 2003
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allow
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Macromedia Flash Player 6.0.x - Flash Cookie Predictable File Location
CVE-2003-1017—remotewindows24 oct 2003
Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web bro
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache cocoon 2.14/2.2 - Directory Traversal
CVE-2003-1172—remotemultiple24 oct 2003
Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
PSCS VPOP3 2.0 Email Server WebAdmin - Cross-Site Scripting
CVE-2003-1522—remotemultiple22 oct 2003
Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Coreutils 4.5.x - LS Width Argument Integer Overflow
CVE-2003-0853—doslinux22 oct 2003
An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or e
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java Virtual Machine 1.x - Slash Path Security Model Circumvention
CVE-2003-0896—dosmultiple22 oct 2003
The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Exchange Server 2000 - XEXCH50 Heap Overflow (PoC) (MS03-046)
CVE-2003-0714—doswindows22 oct 2003
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6 - Scrollbar-Base-Color Partial Denial of Service
CVE-2003-1505—doswindows22 oct 2003
Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or H
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DansGuardian 2.2.x - Denied URL Cross-Site Scripting
CVE-2003-1506—webappscgi22 oct 2003
Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Vivisimo Clustering Engine - Search Script Cross-Site Scripting
CVE-2003-1519—webappsjava21 oct 2003
Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
mIRC 6.1 - 'IRC' Protocol Remote Buffer Overflow
CVE-2003-1336—remotewindows21 oct 2003
Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.
50RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java Plugin 1.4 - Unauthorized Java Applet Floppy Access
CVE-2003-1521—remotewindows21 oct 2003
Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDoc
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
FuzzyMonkey 2.11 - MyClassifieds Email Variable SQL Injection
CVE-2003-1520—webappsphp21 oct 2003
SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Opera 7.11/7.20 HREF - Malformed Server Name Heap Corruption
CVE-2003-0870—dosmultiple20 oct 2003
Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a l
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Bytehoard 0.7 - File Disclosure
CVE-2003-1499—webappsphp20 oct 2003
Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a ..
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Dansie Shopping Cart - Server Error Message Installation Full Path Disclosure
CVE-2003-1517—webappscgi20 oct 2003
cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, whi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Caucho Resin 2.0/2.1 - Multiple HTML Injection / Cross-Site Scripting Vulnerabilities
CVE-2003-1513—webappsjsp20 oct 2003
Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Atrium Software Mercur MailServer 3.3/4.0/4.2 - IMAP AUTH Remote Buffer Overflow
CVE-2003-1177—doswindows20 oct 2003
Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DeskPro 1.1 - Multiple SQL Injections
CVE-1999-0819—webappsphp20 oct 2003
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sun Java Plugin 1.4.2 _01 - Cross-Site Applet Sandbox Security Model Violation
CVE-2003-1516—remotewindows20 oct 2003
The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GoldLink 3.0 - Cookie SQL Injection
CVE-2003-1504—webappsphp18 oct 2003
SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows Messenger Service - Denial of Service (MS03-043)
CVE-2003-0717—doswindows18 oct 2003
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allow
35RIESGO
abrir ↗
← anteriorpágina 542 / 636siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.