Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
AOLServer 3 - 'Authentication String' Remote Buffer Overflow (1)
CVE-2001-1067—remoteunix22 ago 2001
Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary co
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BSDI 3.0/3.1 - Local Kernel Denial of Service
CVE-2001-1133—dosbsd21 ago 2001
Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kerne
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Intego FileGuard 2.0/4.0 - Weak Password Encryption
CVE-2001-1165—localosx20 ago 2001
Intego FileGuard 4.0 uses weak encryption to store user information and passwords, which allows local users to gain priv
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (1)
CVE-2001-0653—locallinux17 ago 2001
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privilege
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (2)
CVE-2001-0653—locallinux17 ago 2001
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privilege
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
glFTPd 1.x - 'LIST' Denial of Service
CVE-2001-0965—dosunix17 ago 2001
glFTPD 1.23 allows remote attackers to cause a denial of service (CPU consumption) via a LIST command with an argument t
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (3)
CVE-2001-0653—locallinux17 ago 2001
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privilege
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sendmail 8.11/8.12 Debugger - Arbitrary Code Execution (4)
CVE-2001-0653—locallinux17 ago 2001
Sendmail 8.10.0 through 8.11.5, and 8.12.0 beta, allows local users to modify process memory and possibly gain privilege
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - SSI Buffer Overrun Privilege Escalation
CVE-2001-0506—localwindows15 ago 2001
Buffer overflow in ssinc.dll in IIS 5.0 and 4.0 allows local users to gain system privileges via a Server-Side Includes
35RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - In-Process Table Privilege Escalation
CVE-2001-0507—localwindows15 ago 2001
IIS 5.0 uses relative paths to find system files that will run in-process, which allows local users to gain privileges v
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Solaris 8 - x86 xlock Heap Overflow
CVE-2001-0652—localsolaris10 ago 2001
Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPAT
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Solaris 2.6/7/8 (SPARC) - xlock Heap Overflow
CVE-2001-0652—localsolaris10 ago 2001
Heap overflow in xlock in Solaris 2.6 through 8 allows local users to gain root privileges via a long (1) XFILESEARCHPAT
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Fetchmail 5.x - IMAP Reply Signed Integer Index
CVE-2001-1009—remoteunix09 ago 2001
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Fetchmail 5.x - POP3 Reply Signed Integer Index
CVE-2001-1009—remoteunix09 ago 2001
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrit
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Avaya Argent Office - DNS Packet Denial of Service
CVE-2001-1259—doswindows07 ago 2001
Avaya Argent Office allows remote attackers to cause a denial of service by sending UDP packets to port 53 with no paylo
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0 - NT4ALL Denial of Service
CVE-2001-1122—doswindows03 ago 2001
Windows NT 4.0 SP 6a allows a local user with write access to winnt/system32 to cause a denial of service (crash in lsas
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpBB 1.4 - SQL Query Manipulation
CVE-2001-1472—webappsphp03 ago 2001
SQL injection vulnerability in prefs.php in phpBB 1.4.0 and 1.4.1 allows remote authenticated users to execute arbitrary
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle 8/9i - DBSNMP Oracle Home Environment Variable Buffer Overflow
CVE-2001-0941—localwindows02 ago 2001
Buffer overflow in dbsnmp in Oracle 8.0.6 through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_H
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SuSE 6.3/6.4/7.0 sdb - Arbitrary Command Execution
CVE-2001-1130—remotelinux02 ago 2001
Sdbsearch.cgi in SuSE Linux 6.0-7.2 could allow remote attackers to execute arbitrary commands by uploading a keylist.tx
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Oracle OTRCREP Oracle 8/9 - Home Environment Variable Buffer Overflow
CVE-2001-0833—localunix02 ago 2001
Buffer overflow in otrcrep in Oracle 8.0.x through 9.0.1 allows local users to execute arbitrary code via a long ORACLE_
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Omnicron OmniHTTPd 2.0.7 - File Corruption / Command Execution
CVE-2001-0113—remotewindows01 ago 2001
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, w
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
GNU findutils 4.0/4.1 - Locate Arbitrary Command Execution
CVE-2001-1036—locallinux01 ago 2001
GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Omnicron OmniHTTPd 2.0.7 - File Corruption / Command Execution
CVE-2001-0114—remotewindows01 ago 2001
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
phpBB 1.x - Page Header Arbitrary Command Execution
CVE-2001-1471—webappsphp31 jul 2001
prefs.php in phpBB 1.4.0 and earlier allows remote authenticated users to execute arbitrary PHP code via an invalid lang
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Windows 98 - ARP Denial of Service
CVE-2001-1055—doswindows30 jul 2001
The Microsoft Windows network stack allows remote attackers to cause a denial of service (CPU consumption) via a flood o
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
id Software Quake 3 Arena Server 1.29 - Buffer Overflow
CVE-2001-1289—dosmultiple29 jul 2001
Quake 3 arena 1.29f and 1.29g allows remote attackers to cause a denial of service (crash) via a malformed connection pa
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SnapStream PVS 1.2 - Plaintext Password
CVE-2001-1107—remotewindows26 jul 2001
SnapStream PVS 1.2a stores its passwords in plaintext in the file SSD.ini, which could allow a remote attacker to gain p
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SimpleServer:WWW 1.0.7/1.0.8/1.13 - Hex Encoded URL Directory Traversal
CVE-2001-1586—remotewindows26 jul 2001
Directory traversal vulnerability in SimpleServer:WWW 1.13 and earlier allows remote attackers to execute arbitrary prog
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SnapStream Personal Video Station 1.2 a - PVS Directory Traversal
CVE-2001-1108—remotewindows26 jul 2001
Directory traversal vulnerability in SnapStream PVS 1.2a allows remote attackers to read arbitrary files via a .. (dot d
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sambar Server 4.x/5.0 - Insecure Default Password Protection
CVE-2001-1106—remotemultiple25 jul 2001
The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program f
23RIESGO
abrir ↗
← anteriorpágina 586 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.