Microsoft DirectWrite / AFDKO – Heap-Based Buffer Overflow in OpenType Font Handling in readEncoding
-----=====[ Background ]=====-----
windows 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
----=====[ Background ]=====-----
-----=====[ Background ]=====-----
# Python 2.7 (included with ImmunityDBG)
Windows: Windows Font Cache Service Insecure Sections EoP
Windows: CmpAddRemoveContainerToCLFSLog Arbitrary File/Directory Creation EoP
# Exploit Title: GSearch v1.0.1.0 - Denial of Service (PoC)
# Exploit Title: EA Origin
# Exploit Title: TuneClone Local Seh Exploit
[+] Credits: John Page (aka hyp3rlinx)
#!/usr/bin/python
#!/usr/bin/python
CVE-2019-0841 BYPASS #2
# VMware Escape Exploit
# Exploit Title: DVDXPlayer 5.5 Pro Local Buffer Overflow with SEH
Press CTRL+V+Enter
import socket, sys, struct
#Exploit Title: Free SMTP Server - Local Denial of Service Crash (PoC)
# Exploit Title: Petraware pTransformer ADC before 2.1.7.22827 allows SQL
# -*- coding: utf-8 -*-
# Exploit Title: Fast AVI MPEG Joiner Dos Exploit
# Exploit Title: Microsoft Internet Explorer Windows 10 1809 17763.316 - Scripting Engine Memory Corruption
#Exploit Title: Cyberoam General Authentication Client 2.1.2.7 - Denial of Service (PoC)
#Exploit Title: Cyberoam Transparent Authentication Suite 2.1.2.5 - 'NetBIOS Name' Denial of Service (PoC)
#Exploit Title: Cyberoam Transparent Authentication Suite 2.1.2.5 - 'Fully Qualified Domain Name' Denial of Service (...
#Exploit Title: Cyberoam SSLVPN Client 1.3.1.30 - 'HTTP Proxy' Denial of Service (PoC)
#Exploit Title: Cyberoam SSLVPN Client 1.3.1.30 - 'Connect To Server' Denial of Service (PoC)
# Title: Axessh 4.2 - 'Log file name' Local Stack-based Buffer Overflow
There is still a vuln in the code triggered by CVE-2019-0841
edit: Figure out how this works for yourself. I can't be bothered. It's a really hard race, doubt anyone will be able...
Windows: CmKeyBodyRemapToVirtualForEnum Arbitrary Key Enumeration EoP
# -*- coding: utf-8 -*-
# -*- coding: utf-8 -*-
# -*- coding: utf-8 -*-
Inject into IE11.
EDIT: Apparently this was patched earlier this month.. so whatever.
#Exploit Title: TapinRadio 2.11.6 - 'Uername' Denial of Service (PoC)
#Exploit Title: TapinRadio 2.11.6 - 'Address' Denial of Service (PoC)
#Exploit Title: RarmaRadio 2.72.3 - 'Username' Denial of Service (PoC)
#Exploit Title: RarmaRadio 2.72.3 - 'Server' Denial of Service (PoC)