Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Local Stack Overflow
CVE-2007-1765localwindows31 mar 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISCO
abrir
Exploit-DBVexDay Proof
IBM Lotus Domino Server 6.5 - Remote Overflow
CVE-2007-1675remotewindows31 mar 2007
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6
35RISCO
abrir
Exploit-DBVexDay Proof
PHP 5.1.6 - 'Msg_Receive()' Memory Allocation Integer Overflow
CVE-2007-1890remotephp31 mar 2007
Integer overflow in the msg_receive function in PHP 4 before 4.4.5 and PHP 5 before 5.2.1, on FreeBSD and possibly other
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 5.1.6 - 'Imap_Mail_Compose()' Remote Buffer Overflow
CVE-2007-1825remotephp31 mar 2007
Buffer overflow in the imap_mail_compose function in PHP 5 before 5.2.1, and PHP 4 before 4.4.5, allows remote attackers
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Local Stack Overflow
CVE-2007-0038localwindows31 mar 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISCO
abrir
Exploit-DBVexDay Proof
PHP-Fusion 6.1.5 Mod Calendar_Panel - 'Show_Event.php' SQL Injection
CVE-2007-1845webappsphp31 mar 2007
SQL injection vulnerability in show_event.php in the Expanded Calendar (calendar_panel) 2.00 module for PHP-Fusion allow
23RISCO
abrir
Exploit-DBVexDay Proof
dproxy-nexgen (Linux x86) - Remote Buffer Overflow
CVE-2007-1866remotelinux_x8630 mar 2007
Stack-based buffer overflow in the dns_decode_reverse_name function in dns_decode.c in dproxy-nexgen allows remote attac
28RISCO
abrir
Exploit-DBVexDay Proof
JC URLShrink 1.3.1 - Remote Code Execution
CVE-2007-1795webappsphp30 mar 2007
JCcorp URLshrink 1.3.1 allows remote attackers to execute arbitrary PHP code via the email address field in an HTML link
23RISCO
abrir
Exploit-DBVexDay Proof
Drake CMS 0.3.7 - '404.php' Local File Inclusion
CVE-2007-1849webappsphp30 mar 2007
Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local
23RISCO
abrir
Exploit-DBVexDay Proof
Snort 2.6.1 (Linux) - DCE/RPC Preprocessor Remote Buffer Overflow
CVE-2006-5276remotelinux30 mar 2007
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RISCO
abrir
Exploit-DBVexDay Proof
IBM Lotus Domino Server 6.5 - 'Username' Remote Denial of Service
CVE-2007-1675doswindows29 mar 2007
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6
35RISCO
abrir
Exploit-DBVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Remote Code
CVE-2007-1785remotewindows29 mar 2007
The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute
28RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.20 with DCCP Support - Memory Disclosure (2)
CVE-2007-1734locallinux28 mar 2007
The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 5.2.1 - 'Session.Save_Path()' TMPDIR open_basedir Restriction Bypass
CVE-2007-1835localphp28 mar 2007
PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR de
23RISCO
abrir
Exploit-DBVexDay Proof
XOOPS module Articles 1.03 - 'index.php?cat_id' SQL Injection
CVE-2007-3311webappsphp28 mar 2007
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to ex
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.20 with DCCP Support - Memory Disclosure (2)
CVE-2007-1730locallinux28 mar 2007
Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.20 with DCCP Support - Memory Disclosure (1)
CVE-2007-1734locallinux27 mar 2007
The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.20 with DCCP Support - Memory Disclosure (1)
CVE-2007-1730locallinux27 mar 2007
Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 4.4.5/4.4.6 - 'session_decode()' Double-Free (PoC)
CVE-2007-1711doslinux27 mar 2007
Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbit
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 4.4.4 - 'Zip_Entry_Read()' Integer Overflow
CVE-2007-1777remotephp27 mar 2007
Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code
28RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - IPv6_SockGlue.c Null Pointer Dereference Denial of Service
CVE-2007-1388doslinux26 mar 2007
The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions,
23RISCO
abrir
Exploit-DBVexDay Proof
Easy File Sharing FTP Server 2.0 (Windows 2000 SP4) - 'PASS' Remote Overflow
CVE-2006-3952remotewindows26 mar 2007
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RISCO
abrir
Exploit-DBVexDay Proof
Mephisto Blog 0.7.3 - Search Function Cross-Site Scripting
CVE-2007-1873webappsphp26 mar 2007
Cross-site scripting (XSS) vulnerability in Mephisto 0.7.3 allows remote attackers to inject arbitrary web script or HTM
23RISCO
abrir
Exploit-DBVexDay Proof
Fizzle 0.5 - RSS Feed HTML Injection
CVE-2007-1678webappsphp26 mar 2007
Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbit
23RISCO
abrir
Exploit-DBVexDay Proof
CcCounter 2.0 - 'index.php' Cross-Site Scripting
CVE-2007-1714webappsphp26 mar 2007
Cross-site scripting (XSS) vulnerability in index.php in CcCounter 2.0 allows remote attackers to inject arbitrary web s
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Recordset Double-Free Memory (MS07-009)
CVE-2006-7206remotewindows26 mar 2007
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating
28RISCO
abrir
Exploit-DBVexDay Proof
PHP < 4.4.5/5.2.1 - '_SESSION' Deserialization Overwrite
CVE-2007-1701locallinux25 mar 2007
PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
PHP < 4.4.5/5.2.1 - '_SESSION unset()' Local Overflow
CVE-2007-1700locallinux25 mar 2007
The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session vari
23RISCO
abrir
Exploit-DBVexDay Proof
Asterisk 1.2.16/1.4.1 - SIP INVITE Remote Denial of Service
CVE-2007-1561dosmultiple25 mar 2007
The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service
28RISCO
abrir
Exploit-DBVexDay Proof
Frontbase 4.2.7 (Windows) - Remote Buffer Overflow
CVE-2007-1511remotewindows25 mar 2007
Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privil
23RISCO
abrir
anteriorpágina 539 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.