Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
dump 0.4b15 (RedHat 6.2) - Local Privilege Escalation
CVE-2000-1009locallinux29 nov 2000
dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to o
23RISCO
abrir
Exploit-DBVexDay Proof
IBM Net.Data 7.0 - Full Path Disclosure
CVE-2000-1110remotemultiple29 nov 2000
document.d2w CGI program in the IBM Net.Data db2www package allows remote attackers to determine the physical path of th
23RISCO
abrir
Exploit-DBVexDay Proof
Caucho Technology Resin 1.2 - JSP Source Disclosure
CVE-2000-1224remotejsp23 nov 2000
Caucho Technology Resin 1.2 and possibly earlier allows remote attackers to view JSP source via an HTTP request to a .js
23RISCO
abrir
Exploit-DBVexDay Proof
Network Associates Webshield SMTP 4.5 - Invalid Outgoing Recipient Field Denial of Service
CVE-2000-1129doswindows23 nov 2000
McAfee WebShield SMTP 4.5 allows remote attackers to cause a denial of service via a malformed recipient field.
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Player 7.0 - '.asx' Remote Buffer Overflow
CVE-2000-1113remotewindows22 nov 2000
Buffer overflow in Microsoft Windows Media Player allows remote attackers to execute arbitrary commands via a malformed
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Player 7.0 - '.wms' Arbitrary Script (MS00-090)
CVE-2000-1112remotewindows22 nov 2000
Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gai
28RISCO
abrir
Exploit-DBVexDay Proof
Microsys CyberPatrol 4.0 4.003/4.0 4.005 - Insecure Registration
CVE-2000-1173remotemultiple22 nov 2000
Microsys CyberPatrol uses weak encryption (trivial encoding) for credit card numbers and uses no encryption for the rema
23RISCO
abrir
Exploit-DBVexDay Proof
Unify eWave ServletExec 3 - .JSP Source Disclosure
CVE-2000-1114remotejsp21 nov 2000
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with
23RISCO
abrir
Exploit-DBVexDay Proof
Solaris 2.x/7.0/8 - 'Catman' Race Condition (1)
CVE-2001-0095localsolaris21 nov 2000
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID tempo
23RISCO
abrir
Exploit-DBVexDay Proof
WU-FTPD 2.6.0 - Remote Command Execution
CVE-2000-0573remotemultiple21 nov 2000
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remo
60RISCO
abrir
Exploit-DBVexDay Proof
BSDi SUIDPerl - Local Stack Buffer Overflow
CVE-1999-0034localbsd21 nov 2000
Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.
23RISCO
abrir
Exploit-DBVexDay Proof
BSDi 3.0/4.0 - 'rcvtty[mh]' Local Privilege Escalation
CVE-2000-1103localbsd21 nov 2000
rcvtty in BSD 3.0 and 4.0 does not properly drop privileges before executing a script, which allows local attackers to g
23RISCO
abrir
Exploit-DBVexDay Proof
vixie-cron - Local Privilege Escalation
CVE-2000-1096locallinux21 nov 2000
crontab by Paul Vixie uses predictable file names for a temporary file and does not properly ensure that the file is own
23RISCO
abrir
Exploit-DBVexDay Proof
Solaris 2.x/7.0/8 - 'Catman' Race Condition (2)
CVE-2001-0095localsolaris21 nov 2000
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID tempo
23RISCO
abrir
Exploit-DBVexDay Proof
Solaris/SPARC 2.7 / 7 locale - Format String
CVE-2000-0844localsolaris20 nov 2000
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISCO
abrir
Exploit-DBVexDay Proof
Jan Hubicka Koules 1.4 - 'Svgalib' Local Buffer Overflow
CVE-2000-1175localunix20 nov 2000
Buffer overflow in Koules 1.4 allows local users to execute arbitrary commands via a long command line argument.
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle 8.x - cmctl Buffer Overflow
CVE-2000-1180locallinux20 nov 2000
Buffer overflow in cmctl program in Oracle 8.1.5 Connection Manager Control allows local users to gain privileges via a
23RISCO
abrir
Exploit-DBVexDay Proof
Markus Triska CGIForum 1.0 - 'thesection' Directory Traversal
CVE-2000-1171remotecgi20 nov 2000
Directory traversal vulnerability in cgiforum.pl script in CGIForum 1.0 allows remote attackers to ready arbitrary files
23RISCO
abrir
Exploit-DBVexDay Proof
BB4 Big Brother Network Monitor 1.5 d2 - 'bb-hist.sh?HISTFILE' File Existence Disclosure
CVE-2000-1177remoteunix20 nov 2000
bb-hist.sh, bb-histlog.sh, bb-hostsvc.sh, bb-rep.sh, bb-replog.sh, and bb-ack.sh in Big Brother (BB) before 1.5d3 allows
23RISCO
abrir
Exploit-DBVexDay Proof
HP-UX 11.00/10.20 crontab - Overwrite Files
CVE-2000-0972doshp-ux19 nov 2000
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target fil
23RISCO
abrir
Exploit-DBVexDay Proof
dump 0.4b15 - Local Privilege Escalation
CVE-2000-1009locallinux19 nov 2000
dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to o
23RISCO
abrir
Exploit-DBVexDay Proof
Ethereal - AFS Buffer Overflow
CVE-2000-1174remoteunix18 nov 2000
Multiple buffer overflows in AFS ACL parser for Ethereal 0.8.13 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (9)
CVE-2000-0884remotewindows18 nov 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (8)
CVE-2000-0884remotewindows18 nov 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (7)
CVE-2000-0884remotewindows18 nov 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (6)
CVE-2000-0884remotewindows18 nov 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
45RISCO
abrir
Exploit-DBVexDay Proof
Oracle (oidldapd connect) - Local Command Line Overflow
CVE-2000-0987locallinux16 nov 2000
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line param
23RISCO
abrir
Exploit-DBVexDay Proof
RedHat 6.2 Restore and Dump - Local Privilege Escalation
CVE-2000-1125locallinux16 nov 2000
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which a
23RISCO
abrir
Exploit-DBVexDay Proof
RedHat 6.2 - '/sbin/restore' Local Privilege Escalation
CVE-2000-1125locallinux16 nov 2000
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which a
23RISCO
abrir
Exploit-DBVexDay Proof
RealServer 5.0/6.0/7.0 - Memory Contents Disclosure
CVE-2000-1181remotemultiple16 nov 2000
Real Networks RealServer 7 and earlier allows remote attackers to obtain portions of RealServer's memory contents, possi
23RISCO
abrir
anteriorpágina 781 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.