Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit200
TinyIdentD 2.2 Stack Buffer Overflow
CVE-2007-271114 may 2007
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long s
50RIESGO
abrir
Metasploit400
Trend Micro ServerProtect 5.58 CreateBinding() Buffer Overflow
CVE-2007-250807 may 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote
60RIESGO
abrir
Metasploit400
Trend Micro ServerProtect 5.58 EarthAgent.EXE Buffer Overflow
CVE-2007-250807 may 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote
60RIESGO
abrir
Metasploit300
Solaris srsexec Arbitrary File Reader
CVE-2007-261707 may 2007
srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file per
38RIESGO
abrir
Metasploit400
IBM TPM for OS Deployment 5.1.0.x rembo.exe Buffer Overflow
CVE-2007-186802 may 2007
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly hand
50RIESGO
abrir
Metasploit200
CA BrightStor ArcServe Media Service Stack Buffer Overflow
CVE-2007-213925 abr 2007
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Me
60RIESGO
abrir
Metasploit600
Apple QTJava toQTPointer() Arbitrary Memory Access
CVE-2007-217523 abr 2007
Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows rem
60RIESGO
abrir
Metasploit200
LANDesk Management Suite 8.7 Alert Service Buffer Overflow
CVE-2007-167413 abr 2007
Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers
60RIESGO
abrir
Metasploit0
MS07-029 Microsoft DNS RPC Service extractQuotedChar() Overflow (SMB)
CVE-2007-174812 abr 2007
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 200
60RIESGO
abrir
Metasploit500
MS07-029 Microsoft DNS RPC Service extractQuotedChar() Overflow (TCP)
CVE-2007-174812 abr 2007
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 200
60RIESGO
abrir
Metasploit300
Roxio CinePlayer ActiveX Control Buffer Overflow
CVE-2007-155911 abr 2007
Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute
50RIESGO
abrir
Metasploit300
HP Mercury Quality Center ActiveX Control ProgColor Buffer Overflow
CVE-2007-181904 abr 2007
Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for M
50RIESGO
abrir
Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP)
CVE-2007-176528 mar 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RIESGO
abrir
Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP)
CVE-2007-003828 mar 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RIESGO
abrir
Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (HTTP)
CVE-2007-003828 mar 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RIESGO
abrir
Metasploit300
WinDVD7 IASystemInfo.DLL ActiveX Control Buffer Overflow
CVE-2007-034820 mar 2007
Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio Ci
50RIESGO
abrir
Metasploit400
D-Link TFTP 1.0 Long Filename Buffer Overflow
CVE-2007-143512 mar 2007
Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GE
50RIESGO
abrir
Metasploit300
Mercury/32 4.01 IMAP LOGIN SEH Buffer Overflow
CVE-2007-137306 mar 2007
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers
50RIESGO
abrir
Metasploit200
PHP 4 unserialize() ZVAL Reference Counter Overflow (Cookie)
CVE-2007-128604 mar 2007
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long
50RIESGO
abrir
Metasploit500
Apache mod_jk 1.2.20 Buffer Overflow
CVE-2007-077402 mar 2007
Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apach
60RIESGO
abrir
Metasploit300
Wireshark chunked_encoding_dissector Function DOS
CVE-2007-338922 feb 2007
Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in a
23RIESGO
abrir
Metasploit600
JBoss JMX Console Deployer Upload and Execute
CVE-2010-0738MEDIUMbajo ataqueransomware20 feb 2007
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RIESGO
abrir
Metasploit600
JBoss JMX Console Deployer Upload and Execute
CVE-2007-103620 feb 2007
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RIESGO
abrir
Metasploit600
JBoss DeploymentFileRepository WAR Deployment (via JMXInvokerServlet)
CVE-2007-103620 feb 2007
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RIESGO
abrir
Metasploit400
Trend Micro ServerProtect 5.58 Buffer Overflow
CVE-2007-107020 feb 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance F
60RIESGO
abrir
Metasploit400
Snort 2 DCE/RPC Preprocessor Buffer Overflow
CVE-2006-527619 feb 2007
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RIESGO
abrir
Metasploit600
Sun Solaris Telnet Remote Authentication Bypass Vulnerability
CVE-2007-088212 feb 2007
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterpr
60RIESGO
abrir
Metasploit300
Trend Micro OfficeScan Client ActiveX Control Buffer Overflow
CVE-2007-032512 feb 2007
Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupIN
50RIESGO
abrir
Metasploit200
CA BrightStor ARCserve for Laptops and Desktops LGServer Buffer Overflow
CVE-2007-044931 ene 2007
Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1
60RIESGO
abrir
Metasploit300
NCTAudioFile2 v2.x ActiveX Control SetFormatLikeSample() Buffer Overflow
CVE-2007-001824 ene 2007
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple prod
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.