Apple iOS/macOS – Sandbox Escape due to Trusted Length Field in Shared Memory used by HID Event Subsystem
io_hideventsystem is a MIG service which provides proxy access to various HID devices for untrusted
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
io_hideventsystem is a MIG service which provides proxy access to various HID devices for untrusted
There is an out-of-bounds read in FEC processing in WebRTC. If a very short RTP packet is received, FEC will assume t...
There is a use-after-free in VP9 processing in WebRTC. In the method RtpFrameReferenceFinder::ManageFrameVp9 the foll...
CVE-2018-15685 - Electron WebPreferences Remote Code Execution
# Exploit Title: Libpango 1.40.8 - Denial of Service (PoC)
#!/usr/bin/python
# Exploit Title: [IBM Sterling B2B Integrator persistent cross-site scripting]
Type confusion can occur when processing a H264 packet. In the method PacketBuffer::FindFrames in modules/video_codin...
There are several calls to memcpy that can overflow the destination buffer in webrtc::UlpfecReceiverImpl::AddReceived...
There is a use-after-free in VP8 block decoding in WebRTC. The contents of the freed block is then treated a pointer,...
There is a heap overflow in Skia when drawing paths with antialiasing turned off. This issue can be triggered in both...
There's a remotely triggerable memory corruption issue in SwiftShader that's reachable from WebGL, resulting from an ...
#######################################
QuickLook is a widely used feature in macOS/iOS which allows you to preview various formats such as pdf, docx, pptx, ...
// Load Int library, thanks saelo!
# Exploit Title: Dicoogle PACS 2.5.0 - Directory Traversal
# pip install PyJWT requests
There is a missing check in VP9 frame processing that could lead to memory corruption.
There is a missing check in VP9 frame processing that could lead to memory corruption.
When v8 decodes the locals of a function, it performs a check:
mptcp_usr_connectx is the handler for the connectx syscall for the AP_MULTIPATH socket family.
getvolattrlist takes a user controlled bufferSize argument via the fgetattrlist syscall.
# Exploit Title: SAP Internet Transaction Server (ITS) 6200.X.X - Session Fixation/ Cross-Site Scripting
# Exploit Title: Multiple XSS Oracle WebCenter Sites (FatWire Content
There's an integer overflow in computing the required allocation size when instantiating a new javascript object.
TIBCO’s JasperReports ( file = new File(/home/rhino/jasperreports...mcat/webapps/jasperserver,"/WEB-INF/jsp/modules/a...
ReportCrash is the daemon responsible for making crash dumps of crashing userspace processes.