Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit400
Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
CVE-2009-3953HIGHbajo ataque13 oct 2009
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x befor
100RIESGO
abrir
Metasploit400
Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
CVE-2009-299013 oct 2009
Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might all
50RIESGO
abrir
Metasploit500
HTTPDX h_handlepeer() Function Buffer Overflow
CVE-2009-371108 oct 2009
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote at
50RIESGO
abrir
Metasploit400
Adobe FlateDecode Stream Predictor 02 Integer Overflow
CVE-2009-3459HIGHbajo ataque08 oct 2009
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RIESGO
abrir
Metasploit400
Adobe FlateDecode Stream Predictor 02 Integer Overflow
CVE-2009-3459HIGHbajo ataque08 oct 2009
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RIESGO
abrir
Metasploit500
AIX Calendar Manager Service Daemon (rpc.cmsd) Opcode 21 Buffer Overflow
CVE-2009-369907 oct 2009
Stack-based buffer overflow in libcsa.a (aka the calendar daemon library) in IBM AIX 5.x through 5.3.10 and 6.x through
50RIESGO
abrir
Metasploit300
Dopewars Denial of Service
CVE-2009-359105 oct 2009
Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with
50RIESGO
abrir
Metasploit300
NTP.org ntpd Reserved Mode Denial of Service
CVE-2009-356304 oct 2009
ntp_request.c in ntpd in NTP before 4.2.4p8, and 4.2.5, allows remote attackers to cause a denial of service (CPU and ba
30RIESGO
abrir
Metasploit400
Xlink FTP Server Buffer Overflow
CVE-2006-579203 oct 2009
Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified
50RIESGO
abrir
Metasploit300
Xlink FTP Client Buffer Overflow
CVE-2006-579203 oct 2009
Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified
50RIESGO
abrir
Metasploit200
EMC ApplicationXtender (KeyWorks) ActiveX Control Buffer Overflow
CVE-2012-251529 sep 2009
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHel
23RIESGO
abrir
Metasploit500
InterSystems Cache UtilConfigHome.csp Argument Buffer Overflow
CVE-2009-20005CRITICAL29 sep 2009
InterSystems Caché UtilConfigHome.csp Stack Buffer Overflow
63RIESGO
abrir
Metasploit600
Persits XUpload ActiveX MakeHttpRequest Directory Traversal
CVE-2009-369329 sep 2009
Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows rem
50RIESGO
abrir
Metasploit600
WinRAR Filename Spoofing
CVE-2014-125119HIGH28 sep 2009
WinRAR < 5.00 Filename Spoofing RCE
36RIESGO
abrir
Metasploit500
Vermillion FTP Daemon PORT Command Memory Corruption
CVE-2010-20115CRITICAL23 sep 2009
Vermillion FTP <= 1.31 Daemon PORT Command Memory Corruption
43RIESGO
abrir
Metasploit600
Adobe RoboHelp Server 8 Arbitrary File Upload and Execute
CVE-2009-306823 sep 2009
Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows
60RIESGO
abrir
Metasploit600
Zabbix Agent net.tcp.listen Command Injection
CVE-2009-450210 sep 2009
The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote att
43RIESGO
abrir
Metasploit600
Zabbix Server Arbitrary Command Execution
CVE-2009-449810 sep 2009
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via
50RIESGO
abrir
Metasploit600
Symantec Altiris Deployment Solution ActiveX Control Arbitrary File Download and Execute
CVE-2009-302809 sep 2009
The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution
50RIESGO
abrir
Metasploit400
MS09-050 Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference
CVE-2009-310307 sep 2009
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RIESGO
abrir
Metasploit300
Microsoft IIS FTP Server LIST Stack Exhaustion
CVE-2009-252103 sep 2009
Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allo
60RIESGO
abrir
Metasploit500
MS09-053 Microsoft IIS FTP Server NLST Response Overflow
CVE-2009-302331 ago 2009
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authen
60RIESGO
abrir
Metasploit600
osCommerce 2.2 Arbitrary PHP Code Execution
CVE-2009-20006CRITICAL31 ago 2009
osCommerce <= 2.2 Admin File Manager Arbitrary PHP Code Execution
63RIESGO
abrir
Metasploit300
Oracle Document Capture 10g ActiveX Control Buffer Overflow
CVE-2007-460728 ago 2009
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RIESGO
abrir
Metasploit300
ProFTP 2.9 Banner Remote Buffer Overflow
CVE-2009-397625 ago 2009
Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execu
43RIESGO
abrir
Metasploit500
ProShow Gold v4.0.2549 (PSH File) Stack Buffer Overflow
CVE-2009-321420 ago 2009
Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code
50RIESGO
abrir
Metasploit500
Xenorate 2.50 (.xpl) Universal Local Buffer Overflow (SEH)
CVE-2009-20003HIGH19 ago 2009
Xenorate <= 2.50 .xpl File Stack-Based Buffer Overflow
36RIESGO
abrir
Metasploit400
VUPlayer M3U Buffer Overflow
CVE-2006-625118 ago 2009
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RIESGO
abrir
Metasploit400
VUPlayer CUE Buffer Overflow
CVE-2009-018218 ago 2009
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RIESGO
abrir
Metasploit300
Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability
CVE-2009-197818 ago 2009
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.