Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
3462 exploits
Metasploit200
Novell NetWare LSASS CIFS.NLM Driver Stack Buffer Overflow
CVE-2005-285221 ene 2007
Unknown vulnerability in CIFS.NLM in Novell Netware 6.5 SP2 and SP3, 5.1, and 6.0 allows remote attackers to cause a den
50RIESGO
abrir
Metasploit200
CA BrightStor ARCserve Message Engine Buffer Overflow
CVE-2007-016911 ene 2007
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup 9.01 through 11.5, Enterprise Backup 10
50RIESGO
abrir
Metasploit200
Novell NetMail IMAP AUTHENTICATE Buffer Overflow
CVE-2005-175807 ene 2007
Buffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers
23RIESGO
abrir
Metasploit300
Apple QuickTime 7.1.3 RTSP URI Buffer Overflow
CVE-2007-001501 ene 2007
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RIESGO
abrir
Metasploit200
Novell NetMail NMAP STOR Buffer Overflow
CVE-2006-642423 dic 2006
Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by ap
50RIESGO
abrir
Metasploit200
Novell NetMail IMAP APPEND Buffer Overflow
CVE-2006-642523 dic 2006
Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated u
50RIESGO
abrir
Metasploit200
Novell NetMail IMAP SUBSCRIBE Buffer Overflow
CVE-2006-676123 dic 2006
Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated u
50RIESGO
abrir
Metasploit500
AstonSoft DeepBurner (DBR File) Path Buffer Overflow
CVE-2006-666519 dic 2006
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute
50RIESGO
abrir
Metasploit500
MailEnable IMAPD (2.34/2.35) Login Request Buffer Overflow
CVE-2006-642311 dic 2006
Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Pro
50RIESGO
abrir
Metasploit300
FileZilla FTP Server Malformed PORT Denial of Service
CVE-2006-656511 dic 2006
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to t
60RIESGO
abrir
Metasploit200
Allied Telesyn TFTP Server 1.9 Long Filename Overflow
CVE-2006-618427 nov 2006
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RIESGO
abrir
Metasploit500
3CTftpSvc TFTP Long Mode Buffer Overflow
CVE-2006-618327 nov 2006
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a d
60RIESGO
abrir
Metasploit500
ProFTPD 1.2 - 1.3.0 sreplace Buffer Overflow (Linux)
CVE-2006-581526 nov 2006
Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably auth
60RIESGO
abrir
Metasploit200
CA BrightStor ARCserve Tape Engine Buffer Overflow
CVE-2006-607621 nov 2006
Buffer overflow in the Tape Engine (tapeeng.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 an
60RIESGO
abrir
Metasploit400
XMPlay 3.3.0.4 (ASX Filename) Buffer Overflow
CVE-2006-606321 nov 2006
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RIESGO
abrir
Metasploit300
MS06-067 Microsoft Internet Explorer Daxctle.OCX KeyFrame Method Heap Buffer Overflow Vulnerability
CVE-2006-477714 nov 2006
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RIESGO
abrir
Metasploit0
MS06-070 Microsoft Workstation Service NetpManageIPCConnect Overflow
CVE-2006-469114 nov 2006
Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Wi
60RIESGO
abrir
Metasploit400
MS06-066 Microsoft Services nwapi32.dll Module Exploit
CVE-2006-468814 nov 2006
Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 al
60RIESGO
abrir
Metasploit400
MS06-066 Microsoft Services nwwks.dll Module Exploit
CVE-2006-468814 nov 2006
Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 al
60RIESGO
abrir
Metasploit200
Omni-NFS Server Buffer Overflow
CVE-2006-578006 nov 2006
Stack-based buffer overflow in nfsd.exe in XLink Omni-NFS Server 5.2 allows remote attackers to execute arbitrary code v
50RIESGO
abrir
Metasploit600
America Online ICQ ActiveX Control Arbitrary File Download and Execute
CVE-2006-565006 nov 2006
The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute
50RIESGO
abrir
Metasploit300
TikiWiki Information Disclosure
CVE-2006-570201 nov 2006
Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_m
50RIESGO
abrir
Metasploit300
Microsoft Windows NAT Helper Denial of Service
CVE-2006-561426 oct 2006
Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, a
60RIESGO
abrir
Metasploit500
Novell eDirectory NDS Server Host Header Overflow
CVE-2006-547821 oct 2006
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell Ne
60RIESGO
abrir
Metasploit600
Solaris libnspr NSPR_LOG_FILE Privilege Escalation
CVE-2006-484211 oct 2006
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment v
38RIESGO
abrir
Metasploit300
MS06-071 Microsoft Internet Explorer XML Core Services HTTP Request Handling
CVE-2006-574510 oct 2006
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML
60RIESGO
abrir
Metasploit200
SHTTPD URI-Encoded POST Request Overflow
CVE-2006-521606 oct 2006
Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary cod
50RIESGO
abrir
Metasploit200
CA BrightStor ARCserve Message Engine Heap Overflow
CVE-2006-514305 oct 2006
Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve B
60RIESGO
abrir
Metasploit500
NaviCOPA 2.0.1 URL Handling Buffer Overflow
CVE-2006-511228 sep 2006
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RIESGO
abrir
Metasploit500
TFTPDWIN v0.4.2 Long Filename Buffer Overflow
CVE-2006-494821 sep 2006
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.