Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (2)
CVE-2001-0500—remotewindows21 jun 2001
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
KDE KTVision 0.1 - File Overwrite
CVE-2001-0782—localunix21 jun 2001
KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configu
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
cfingerd 1.4.1/1.4.2/1.4.3 Utilities - Local Buffer Overflow (1)
CVE-2001-0735—localunix21 jun 2001
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute a
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
eXtremail 1.x/2.1 - Remote Format String (1)
CVE-2001-1078—doslinux21 jun 2001
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privile
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
W3M 0.1/0.2 - Malformed MIME Header Buffer Overflow
CVE-2001-0700—remotefreebsd19 jun 2001
Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MI
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Tarantella Enterprise 3 3.x - 'TTAWebTop.cgi' Arbitrary File Viewing
CVE-2001-0805—remotecgi18 jun 2001
Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to rea
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DC Scripts DCShop Beta 1.0 02 - File Disclosure (1)
CVE-2001-0821—remotecgi18 jun 2001
The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SGI Performance Co-Pilot 2.1.x/2.2 - pmpost Symbolic Link
CVE-2001-0823—localirix18 jun 2001
The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink att
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
DC Scripts DCShop Beta 1.0 02 - File Disclosure (2)
CVE-2001-0821—remotecgi18 jun 2001
The default configuration of DCShop 1.002 beta places sensitive files in the cgi-bin directory, which could allow remote
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Internet Software Solutions Air Messenger LAN Server 3.4.2 - Full Path Disclosure
CVE-2001-0788—remotewindows18 jun 2001
Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute pat
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microburst uDirectory 2.0 - Remote Command Execution
CVE-2001-1160—remotecgi18 jun 2001
udirectory.pl in Microburst Technologies uDirectory 2.0 and earlier allows remote attackers to execute arbitrary command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (4)
CVE-2001-0500—remotewindows18 jun 2001
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (3)
CVE-2001-0500—remotewindows18 jun 2001
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (PoC)
CVE-2001-0500—doswindows18 jun 2001
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ghttpd 1.4 - Daemon Buffer Overflow
CVE-2001-0820—remotelinux17 jun 2001
Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are pas
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
ghttpd 1.4 - Daemon Buffer Overflow
CVE-2002-1904—remotelinux17 jun 2001
Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Rxvt 2.6.1/2.6.2 - Local Buffer Overflow
CVE-2001-1077—locallinux15 jun 2001
Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
NetSQL 1.0 - Remote Buffer Overflow
CVE-2001-1163—remotelinux15 jun 2001
Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT ar
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
BestCrypt 0.6/0.7/0.8 - BCTool UMount Buffer Overflow
CVE-2001-0759—locallinux14 jun 2001
Buffer overflow in bctool in Jetico BestCrypt 0.8.1 and earlier allows local users to execute arbitrary code via a file
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
SiteWare 2.5/3.0/3.1 Editor Desktop - Directory Traversal
CVE-2001-0555—webappsjava13 jun 2001
ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot do
28RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (3)
CVE-2001-0925—remotemultiple13 jun 2001
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Juergen Schoenwaelder scotty 2.1.x - ntping Buffer Overflow
CVE-2001-0764—localunix13 jun 2001
Buffer overflow in ntping in scotty 2.1.0 allows local users to execute arbitrary code via a long hostname as a command
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (1)
CVE-2001-0925—remotemultiple13 jun 2001
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (4)
CVE-2001-0925—remotemultiple13 jun 2001
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
MDBms 0.96/0.99 - Query Display Buffer Overflow
CVE-2001-0818—remotelinux12 jun 2001
A buffer overflow the '\s' console command in MDBMS 0.99b9 and earlier allows remote attackers to execute arbitrary comm
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Rumpus FTP Server 1.3.x/2.0.3 - Stack Overflow Denial of Service
CVE-2001-0706—dososx12 jun 2001
Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir comma
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Sean MacGuire Big Brother 1.0/1.3/1.4 - CGI File Creation
CVE-2000-0639—localcgi11 jun 2001
The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows rem
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
XFree86 X11R6 3.3.2 XMan - ManPath Environment Variable Buffer Overflow
CVE-2001-1178—locallinux11 jun 2001
Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable.
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
TransSoft Broker FTP Server 3.0/4.0/4.7/5.x - CWD Buffer Overflow
CVE-2001-0688—remotewindows10 jun 2001
Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or C
23RIESGO
abrir ↗
Exploit-DB✓ VexDay Proof
Apache 1.3.14 - Mac File Protection Bypass
CVE-2001-0766—remoteosx10 jun 2001
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a UR
23RIESGO
abrir ↗
← anteriorpágina 589 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.