Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
3.462 exploits
Metasploit200
Samba lsa_io_trans_names Heap Overflow
CVE-2007-244614 mai 2007
Multiple heap-based buffer overflows in the NDR parsing in smbd in Samba 3.0.0 through 3.0.25rc3 allow remote attackers
60RISCO
abrir
Metasploit300
Solaris srsexec Arbitrary File Reader
CVE-2007-261707 mai 2007
srsexec in Sun Remote Services (SRS) Net Connect Software Proxy Core package in Sun Solaris 10 does not enforce file per
38RISCO
abrir
Metasploit400
Trend Micro ServerProtect 5.58 CreateBinding() Buffer Overflow
CVE-2007-250807 mai 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote
60RISCO
abrir
Metasploit400
Trend Micro ServerProtect 5.58 EarthAgent.EXE Buffer Overflow
CVE-2007-250807 mai 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote
60RISCO
abrir
Metasploit400
IBM TPM for OS Deployment 5.1.0.x rembo.exe Buffer Overflow
CVE-2007-186802 mai 2007
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly hand
50RISCO
abrir
Metasploit200
CA BrightStor ArcServe Media Service Stack Buffer Overflow
CVE-2007-213925 abr 2007
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Me
60RISCO
abrir
Metasploit600
Apple QTJava toQTPointer() Arbitrary Memory Access
CVE-2007-217523 abr 2007
Apple QuickTime Java extensions (QTJava.dll), as used in Safari and other browsers, and when Java is enabled, allows rem
60RISCO
abrir
Metasploit200
LANDesk Management Suite 8.7 Alert Service Buffer Overflow
CVE-2007-167413 abr 2007
Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers
60RISCO
abrir
Metasploit500
MS07-029 Microsoft DNS RPC Service extractQuotedChar() Overflow (TCP)
CVE-2007-174812 abr 2007
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 200
60RISCO
abrir
Metasploit0
MS07-029 Microsoft DNS RPC Service extractQuotedChar() Overflow (SMB)
CVE-2007-174812 abr 2007
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 200
60RISCO
abrir
Metasploit300
Roxio CinePlayer ActiveX Control Buffer Overflow
CVE-2007-155911 abr 2007
Multiple stack-based buffer overflows in SonicDVDDashVRNav.dll in Roxio CinePlayer 3.2 allow remote attackers to execute
50RISCO
abrir
Metasploit300
HP Mercury Quality Center ActiveX Control ProgColor Buffer Overflow
CVE-2007-181904 abr 2007
Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for M
50RISCO
abrir
Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP)
CVE-2007-003828 mar 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISCO
abrir
Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP)
CVE-2007-176528 mar 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISCO
abrir
Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (HTTP)
CVE-2007-003828 mar 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISCO
abrir
Metasploit300
WinDVD7 IASystemInfo.DLL ActiveX Control Buffer Overflow
CVE-2007-034820 mar 2007
Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio Ci
50RISCO
abrir
Metasploit400
D-Link TFTP 1.0 Long Filename Buffer Overflow
CVE-2007-143512 mar 2007
Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GE
50RISCO
abrir
Metasploit300
Mercury/32 4.01 IMAP LOGIN SEH Buffer Overflow
CVE-2007-137306 mar 2007
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers
50RISCO
abrir
Metasploit200
PHP 4 unserialize() ZVAL Reference Counter Overflow (Cookie)
CVE-2007-128604 mar 2007
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long
50RISCO
abrir
Metasploit500
Apache mod_jk 1.2.20 Buffer Overflow
CVE-2007-077402 mar 2007
Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apach
60RISCO
abrir
Metasploit300
Wireshark chunked_encoding_dissector Function DOS
CVE-2007-338922 fev 2007
Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a crafted chunked encoding in a
23RISCO
abrir
Metasploit400
Trend Micro ServerProtect 5.58 Buffer Overflow
CVE-2007-107020 fev 2007
Multiple stack-based buffer overflows in Trend Micro ServerProtect for Windows and EMC 5.58, and for Network Appliance F
60RISCO
abrir
Metasploit600
JBoss JMX Console Deployer Upload and Execute
CVE-2010-0738MEDIUMsob ataqueransomware20 fev 2007
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir
Metasploit600
JBoss DeploymentFileRepository WAR Deployment (via JMXInvokerServlet)
CVE-2007-103620 fev 2007
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RISCO
abrir
Metasploit600
JBoss JMX Console Deployer Upload and Execute
CVE-2007-103620 fev 2007
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RISCO
abrir
Metasploit400
Snort 2 DCE/RPC Preprocessor Buffer Overflow
CVE-2006-527619 fev 2007
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RISCO
abrir
Metasploit600
Sun Solaris Telnet Remote Authentication Bypass Vulnerability
CVE-2007-088212 fev 2007
Argument injection vulnerability in the telnet daemon (in.telnetd) in Solaris 10 and 11 (SunOS 5.10 and 5.11) misinterpr
60RISCO
abrir
Metasploit300
Trend Micro OfficeScan Client ActiveX Control Buffer Overflow
CVE-2007-032512 fev 2007
Multiple buffer overflows in the Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control in OfficeScanSetupIN
50RISCO
abrir
Metasploit200
CA BrightStor ARCserve for Laptops and Desktops LGServer Buffer Overflow
CVE-2007-044931 jan 2007
Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1
60RISCO
abrir
Metasploit300
NCTAudioFile2 v2.x ActiveX Control SetFormatLikeSample() Buffer Overflow
CVE-2007-001824 jan 2007
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple prod
50RISCO
abrir
anteriorpágina 97 / 116próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.