macOS < 10.14.3 / iOS < 12.1.3 XNU - 'vm_map_copy' Optimization which Requires Atomicity isn't Atomic
vm_map_copyin_internal in vm_map.c converts a region of a vm_map into "copied in" form, constructing a vm_map_copy
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
vm_map_copyin_internal in vm_map.c converts a region of a vm_map into "copied in" form, constructing a vm_map_copy
It's possible that this should be two separate issues but I'm filing it as one as I'm still understanding
_xpc_serializer_unpack in libxpc parses mach messages which contain xpc messages.
macOS 10.13.4 introduced the file bsd/net/if_ports_used.c, which defines sysctls for inspecting
# Exploit Title: Access Manager Unauthenticated Insecure Direct Object Reference (IDOR)
# Exploit Title: Lua 5.3.5
# Exploit Title: SSHtranger Things
# Exploit Title: [Cross-site Scripting (XSS)]
The doesGC function simply takes a node, and tells if it might cause a garbage collection. This function is used to d...
#!/bin/bash
#Exploit Title: OpenSource ERP SQL Injection
The following crash due to a heap-based out-of-bounds memory read can be observed in an ASAN build of Wireshark, by f...
bool JSArray::shiftCountWithArrayStorage(VM& vm, unsigned startIndex, unsigned count, ArrayStorage* storage)
// ./jsc --useConcurrentJIT=false ~/test.js
import socket
# Exploit Title: [XML External Entity Injection (XXE)]
# Exploit Title: Unrestricted file upload in Adobe ColdFusion 2018
# Exploit Title: Apache OFBiz v16.11.05 - Stored Cross-Site Scripting Vulnerability
# Exploit Author: bzyo
When the mmap() syscall is invoked on a POSIX shared memory segment
#!/usr/bin/env python3
#!/usr/bin/env python3
The following crash due to a heap-based out-of-bounds read can be observed in an ASAN build of Wireshark (current git...
The following crash due to a stack-based out-of-bounds memory access can be observed in an ASAN build of Wireshark (c...
This is simillar to issue 1263 . When hoisting a function onto the outer scope, if it overwrites the iteration varia...
case ArrayPushIntrinsic: {
When a for-in loop is executed, a JSPropertyNameEnumerator object is created at the beginning and used to store the i...
#!/bin/bash
# Exploit Title: Nutanix AOS & Prism - SFTP Authentication Bypass
// All respects goes to Zhiyi Zhang of 360 ESG Codesafe Team
#CVE-2018-14665 - a LPE exploit via http://X.org fits in a tweet
IOHIDResourceQueue inherits from IOSharedDataQueue and adds its own ::enqueueReport method,
io_hideventsystem sets up a shared memory event queue; at the end of this shared memory buffer it puts