Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.295exploits catalogados
36.048CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DBVexDay Proof
IBM AIX 5.x - 'Diag' Local Privilege Escalation
CVE-2004-1329localaix20 dic 2004
Untrusted execution path vulnerability in the diag commands (1) lsmcode, (2) diag_exec, (3) invscout, and (4) invscoutd
23RIESGO
abrir
Exploit-DBVexDay Proof
Ultrix 4.5/MIPS - dxterm 0 Local Buffer Overflow
CVE-2004-1326localultrix20 dic 2004
Buffer overflow in dxterm in Ultrix 4.5 allows local users to execute arbitrary code via a long -setup parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Player 9.0 - ActiveX Control File Enumeration
CVE-2004-1325remotewindows18 dic 2004
The getItemInfoByAtom function in the ActiveX control for Microsoft Windows Media Player 9.0 returns a 0 if the file doe
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Player 9.0 - ActiveX Control Media File Attribute Corruption
CVE-2004-1324remotewindows18 dic 2004
The Microsoft Windows Media Player 9.0 ActiveX control may allow remote attackers to execute arbitrary web script in the
28RIESGO
abrir
Exploit-DBVexDay Proof
Kayako eSupport 2.x - Ticket System Multiple SQL Injections
CVE-2004-1413webappsphp18 dic 2004
Multiple SQL injection vulnerabilities in Kayako eSupport 2.x allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Exploit-DBVexDay Proof
Kayako eSupport 2.x - 'index.php' Knowledgebase Cross-Site Scripting
CVE-2004-1412webappsphp18 dic 2004
Cross-site scripting (XSS) vulnerability in index.php in Kayako eSupport 2.x allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
O3Read 0.0.3 - HTML Parser Buffer Overflow
CVE-2004-1288remotelinux17 dic 2004
Buffer overflow in the parse_html function in o3read.c for o3read 0.0.3 allows remote attackers to execute arbitrary cod
28RIESGO
abrir
Exploit-DBVexDay Proof
Gadu-Gadu 6.0 - URL Parser JavaScript Cross-Site Scripting
CVE-2004-1410remotewindows17 dic 2004
Cross-site scripting (XSS) vulnerability in Gadu-Gadu build 155 and earlier allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
MediaWiki 1.3.x - Arbitrary Script Upload
CVE-2004-1405webappsphp16 dic 2004
MediaWiki 1.3.8 and earlier, when used with Apache mod_mime, does not properly handle files with two file extensions, su
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.28/2.6.9 - 'ip_options_get' Local Overflow
CVE-2004-1335doslinux16 dic 2004
Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of ser
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.28/2.6.9 - vc_resize int Local Overflow
CVE-2004-1333doslinux16 dic 2004
Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a d
23RIESGO
abrir
Exploit-DBVexDay Proof
Xine-Lib 0.9/1 - Remote Client-Side Buffer Overflow
CVE-2004-1300remotelinux16 dic 2004
Buffer overflow in the open_aiff_file function in demux_aiff.c for xine-lib (libxine) 1-rc7 allows remote attackers to e
23RIESGO
abrir
Exploit-DBVexDay Proof
XLReader 0.9 - Remote Client-Side Buffer Overflow
CVE-2004-1301remotemultiple16 dic 2004
Buffer overflow in the book_format_sql function in format.c for xlreader 0.9.0 allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
IkonBoard 3.x - Multiple SQL Injections
CVE-2004-1406webappscgi16 dic 2004
SQL injection vulnerability in ikonboard.cgi in Ikonboard 3.1.0 through 3.1.3 allows remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
PHP 4/5 - 'addslashes()' Null Byte Bypass
CVE-2004-1020remotephp16 dic 2004
The addslashes function in PHP 4.3.9 does not properly escape a NULL (/0) character, which may allow remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
RTF2LATEX2E 1.0 - Remote Stack Buffer Overflow
CVE-2004-1293remotelinux16 dic 2004
Buffer overflow in the ReadFontTbl function in reader.c for rtf2latex2e 1.0fc2 allows remote attackers to execute arbitr
28RIESGO
abrir
Exploit-DBVexDay Proof
WinRAR 3.4.1 - Corrupt '.ZIP' File
CVE-2004-1254localwindows16 dic 2004
WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing
28RIESGO
abrir
Exploit-DBVexDay Proof
phpGroupWare 0.9.x - 'index.php' Multiple SQL Injections
CVE-2004-1385webappsphp15 dic 2004
phpGroupWare 0.9.16.003 and earlier allows remote attackers to gain sensitive information via (1) unexpected characters
23RIESGO
abrir
Exploit-DBVexDay Proof
phpGroupWare 0.9.x - 'viewticket_details.php?ticket_id' Cross-Site Scripting
CVE-2004-1384webappsphp15 dic 2004
Multiple cross-site scripting (XSS) vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to inj
23RIESGO
abrir
Exploit-DBVexDay Proof
NASM 0.98.x - Error Preprocessor Directive Buffer Overflow
CVE-2004-1287remotelinux15 dic 2004
Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a
28RIESGO
abrir
Exploit-DBVexDay Proof
ASP2PHP 0.76.23 - Preparse Token Variable Buffer Overflow
CVE-2004-1261remotewindows15 dic 2004
Multiple buffer overflows in the preparse function in asp2php 0.76.23 allow remote attackers to execute arbitrary code v
23RIESGO
abrir
Exploit-DBVexDay Proof
abctab2ps 1.6.3 - 'Write_Heading' '.ABC' Remote Buffer Overflow
CVE-2004-1260remotewindows15 dic 2004
Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abct
28RIESGO
abrir
Exploit-DBVexDay Proof
ABCPP 1.3 - Directive Handler Buffer Overflow
CVE-2004-1259remotewindows15 dic 2004
Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenText FirstClass 8.0 - HTTP Daemon /Search Remote Denial of Service
CVE-2004-2496doswindows15 dic 2004
The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availab
23RIESGO
abrir
Exploit-DBVexDay Proof
IWebNegar - Multiple SQL Injections
CVE-2004-1402webappsphp15 dic 2004
SQL injection vulnerability in iWebNegar allows remote attackers to execute arbitrary SQL commands via (1) the string pa
23RIESGO
abrir
Exploit-DBVexDay Proof
phpGroupWare 0.9.x - 'viewticket_details.php?ticket_id' SQL Injection
CVE-2004-1383webappsphp15 dic 2004
Multiple SQL injection vulnerabilities in phpGroupWare 0.9.16.003 and earlier allow remote attackers to execute arbitrar
23RIESGO
abrir
Exploit-DBVexDay Proof
abctab2ps 1.6.3 - 'Trim_Title' '.ABC' File Remote Buffer Overflow
CVE-2004-1260remotewindows15 dic 2004
Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abct
28RIESGO
abrir
Exploit-DBVexDay Proof
PCAL 4.x - Calendar File 'get_holiday' Remote Buffer Overflow
CVE-2004-1289remotelinux15 dic 2004
Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for p
28RIESGO
abrir
Exploit-DBVexDay Proof
Yanf 0.4 - HTTP Response Buffer Overflow
CVE-2004-1303remotemultiple15 dic 2004
Buffer overflow in the get function in get.c for Yanf 0.4 allows remote malicious web servers to execute arbitrary code
23RIESGO
abrir
Exploit-DBVexDay Proof
Michael Kohn VB2C 0.02 - '.FRM' File Remote Buffer Overflow
CVE-2004-1298remotewindows15 dic 2004
Buffer overflow in the parse function in vb2c.c for vb2c 0.02 allows remote attackers to execute arbitrary code via a cr
23RIESGO
abrir
anteriorpágina 685 / 816siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.