Chrome V8 JIT – Arrow Function Scope Fixing Bug
When the parser parses the parameter list of an arrow function contaning destructuring assignments, it can't distingu...
multiple 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
When the parser parses the parameter list of an arrow function contaning destructuring assignments, it can't distingu...
Here's a snippet of AsyncGeneratorReturn. (https://cs.chromium.org/chromium/src/v8/src/builtins/builtins-async-genera...
https://cs.chromium.org/chromium/src/v8/src/compiler/node-properties.cc?rcl=df84e87191022bf6914f9570069908f10b303245&...
The attached swf file causes and out-of-bounds write in blur filtering.
The attached image causes an info leak in image inflation. It occasionally crashes when rendered, otherwise it displa...
The attached fuzzed swf file causes heap or stack corruption (depending on platform) when rendering a slab.
The attached fuzzed swf file causes heap overflow when playing a sound.
# Exploit Title: Buffer-overflow in RSVG while converting a malformed svg
=============================================
I think this commit has introduced the bug: https://chromium.googlesource.com/v8/v8.git/+/9884bc5dee488bf206655f07b8a...
When a WebAssembly binary is parsed in ModuleParser::parse, it is expected to contain certain sections in a certain o...
#!/usr/bin/env python
Here's a snippet of the method.
# Exploit Title: Open-AuditIT Professional 2.1 - Cross-Site Request Forgery (CSRF)
var login = 'testuser'; //логин пользователя
---------------------------------------------------------------------
#!/usr/bin/env python3
Prisma Industriale Checkweigher PrismaWEB 1.21 Authentication Bypass
In the current implementation, the bytecode generator also emits empty jump tables.
I think this commit has introduced the bug.
I think this commit has introduced the bugs: https://chromium.googlesource.com/v8/v8/+/c22ca7f73ba92f22d0cd29b06bb294...
Exploit Title: Bravo Tejari Web Portal-CSRF
-----------------------------------------------------
# Exploit Title: antMan
Here'a snippet of TranslatedState::MaterializeCapturedObjectAt.
Here's a snippet of the MigrateFastToFast function which is used to create a new PropertyArray object.
I took a look at torrent file parsing in libtransmission, there are a few integer overflows because the tr_new/tr_new...
# Exploit title: Wavpack 5.1.0 - Denial of Service
By default, utorrent create an HTTP RPC server on port 10000 (uTorrent classic) or 19575 (uTorrent web). There are nu...
# Exploit Title: Oracle Primavera P6 Enterprise Project Portfolio Management HTTP Response Splitting
# Exploit Title: Exploit Denial of Service JBoss Remoting (4447/9999)
Here's a snippet of the method.
Related to issue 1490 .
This vulnerability relies on several minor oversights in the handling of shading patterns in pdfium, I'll try to deta...
# Exploit Author: Juan Sacco - http://exploitpack.com
#!/usr/bin/env python
Claymore’s Dual GPU Miner 10.5 and below is vulnerable to a format strings vulnerability. This allows an unauthentica...
# Exploit Title: Oracle Hospitality Simphony (MICROS) directory traversal