Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

77,900cataloged exploits
35,840CVEs with public exploitation
24,695lab-tested
24,458 exploits
Exploit-DBVexDay Proof
LibPNG 1.2.5 - 'png_jmpbuf()' Local Buffer Overflow
CVE-2004-0597locallinux13 Aug 2004
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute a
45RISK
open
Exploit-DBVexDay Proof
GV PostScript Viewer - Remote Buffer Overflow (1)
CVE-2004-1717remotelinux13 Aug 2004
Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary
23RISK
open
Exploit-DBVexDay Proof
Apple Mac OSX 10.3.3 - AppleFileServer Overflow Remote Code Execution
CVE-2004-0430remoteosx13 Aug 2004
Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitr
50RISK
open
Exploit-DBVexDay Proof
Remote CVS 1.11.15 - 'error_prog_name' Arbitrary Code Execution
CVE-2004-0416remotelinux13 Aug 2004
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may a
28RISK
open
Exploit-DBVexDay Proof
Internet Security Systems BlackICE PC Protection 3.6 - Firewall.INI Local Buffer Overrun
CVE-2004-1714doswindows11 Aug 2004
BlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.i
23RISK
open
Exploit-DBVexDay Proof
LibPNG Graphics Library - Remote Buffer Overflow
CVE-2004-0597remotelinux11 Aug 2004
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute a
45RISK
open
Exploit-DBVexDay Proof
GNU Mailutils 0.6 - Mail Email Header Buffer Overflow
CVE-2005-1520remotelinux10 Aug 2004
Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions befo
23RISK
open
Exploit-DBVexDay Proof
OllyDbg 1.10 - Format String
CVE-2004-0733localwindows10 Aug 2004
Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly ex
23RISK
open
Exploit-DBVexDay Proof
GNU CFEngine 2.0.x/2.1 - AuthenticationDialogue Remote Heap Buffer Overrun (1)
CVE-2004-1701doslinux09 Aug 2004
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote
28RISK
open
Exploit-DBVexDay Proof
GNU CFEngine 2.0.x/2.1 - AuthenticationDialogue Remote Heap Buffer Overrun (2)
CVE-2004-1701remotelinux09 Aug 2004
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote
28RISK
open
Exploit-DBVexDay Proof
xine 0.99.2 - Remote Stack Overflow
CVE-2004-1475remotelinux09 Aug 2004
Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1)
23RISK
open
Exploit-DBVexDay Proof
Pavuk Digest - Authentication Remote Buffer Overflow
CVE-2004-1437remotelinux08 Aug 2004
Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attacke
28RISK
open
Exploit-DBVexDay Proof
PHP 4.3.7 - 'php-exec-dir' Patch Command Access Restriction Bypass
CVE-2004-2692webappsphp08 Aug 2004
The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass rest
23RISK
open
Exploit-DBVexDay Proof
RhinoSoft Serv-U FTP Server 3.x < 5.x - Local Privilege Escalation
CVE-2004-2532localwindows08 Aug 2004
Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users t
28RISK
open
Exploit-DBVexDay Proof
Microsoft Messenger (Linux) - Denial of Service (MS03-043)
CVE-2003-0717doswindows08 Aug 2004
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allow
35RISK
open
Exploit-DBVexDay Proof
CVSTrac - Arbitrary Code Execution
CVE-2004-1456remotelinux06 Aug 2004
filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.
28RISK
open
Exploit-DBVexDay Proof
BlackJumboDog FTP Server - Remote Buffer Overflow
CVE-2004-1439remotewindows05 Aug 2004
Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1)
28RISK
open
Exploit-DBVexDay Proof
Ethereal 0.x - Multiple iSNS / SMB / SNMP Protocol Dissector Vulnerabilities
CVE-2004-0633remotelinux05 Aug 2004
The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abor
28RISK
open
Exploit-DBVexDay Proof
Free Web Chat Initial Release - UserManager.java Null Pointer Denial of Service
CVE-2004-2646dosmultiple04 Aug 2004
The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (unca
23RISK
open
Exploit-DBVexDay Proof
SoX - '.wav' Local Buffer Overflow
CVE-2004-0557locallinux04 Aug 2004
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allo
28RISK
open
Exploit-DBVexDay Proof
eNdonesia 8.3 - Search Form Cross-Site Scripting
CVE-2004-2670webappsphp04 Aug 2004
Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitra
23RISK
open
Exploit-DBVexDay Proof
Free Web Chat Initial Release - Connection Saturation Denial of Service
CVE-2004-2647dosmultiple04 Aug 2004
Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from t
23RISK
open
Exploit-DBVexDay Proof
Acme thttpd 2.0.7 - Directory Traversal
CVE-2004-2628remotewindows04 Aug 2004
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to
23RISK
open
Exploit-DBVexDay Proof
Oracle 9i - Multiple Vulnerabilities
CVE-2004-1364remoteunix04 Aug 2004
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries
28RISK
open
Exploit-DBVexDay Proof
OpenFTPd 0.30.1 - message system Remote Shell
CVE-2004-2523remotelinux04 Aug 2004
Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows rem
23RISK
open
Exploit-DBVexDay Proof
Microsoft Internet Explorer - 'mshtml.dll' Remote Null Pointer Crash
CVE-2004-2434doswindows04 Aug 2004
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with
35RISK
open
Exploit-DBVexDay Proof
Linux Kernel 2.4.26 - File Offset Pointer Handling Memory Disclosure
CVE-2004-0415locallinux04 Aug 2004
Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portio
23RISK
open
Exploit-DBVexDay Proof
OpenFTPd 0.30.2 - Remote Overflow
CVE-2004-2523remotelinux03 Aug 2004
Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows rem
23RISK
open
Exploit-DBVexDay Proof
IBM Tivoli Directory Server 3.2.2/4.1 - LDACGI Directory Traversal
CVE-2004-2526remotewindows02 Aug 2004
Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers t
23RISK
open
Exploit-DBVexDay Proof
Webcam Corp Webcam Watchdog 4.0.1 - 'sresult.exe' Cross-Site Scripting
CVE-2004-2528remotecgi02 Aug 2004
Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbi
23RISK
open
previouspage 696 / 816next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.