Easy CD DVD Copy 1.3.24 – Local Buffer Overflow (SEH)
#!/usr/bin/python
windows 相关平台内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
#!/usr/bin/python
#!/usr/bin/python
# SWAMI KARUPASAMI THUNAI
Windows: Desktop Bridge Virtual Registry NtLoadKey Arbitrary File Read/Write EoP
There is a vulnerability in Internet Explorer that could potentially be used for memory disclosure.
CVE-2016-1960 and ASM.JS JIT-Spray
CVE-2016-2819 and ASM.JS JIT-Spray
#!/usr/bin/env python
# Exploit Title: Arbitrary Code Execution
#!/usr/bin/python2.7
###############################################################################
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
ActivePDF Toolkit < 8.1.0 multiple RCE
#!/usr/bin/python
#!/usr/bin/perl
[+] Credits: John Page (aka hyp3rlinx)
[+] Credits: John Page (aka hyp3rlinx)
#!/usr/bin/python
#!/usr/bin/python
# Exploit Title: Microsoft Windows SMB Client Null Pointer Dereference Denial of Service
#!/usr/bin/python
# Exploit Title: Parallels Remote Application Server (RAS) 15.5 Path Traversal
Title: Armadito Antivirus - Malware Detection Bypass
#!/usr/bin/env python
# Exploit Title: Disk Savvy Enterprise v10.4.18 Server - Unauthenticated Remote Buffer Overflow SEH
# Exploit Author: Juan Sacco
Windows: StorSvc SvcMoveFileInheritSecurity Arbitrary File Creation EoP
Windows: Constrained Impersonation Capability EoP
Windows: NPFS Symlink Security Feature Bypass/Elevation of Privilege/Dangerous Behavior
Windows: Global Reparse Point Security Feature Bypass/Elevation of Privilege
We have discovered a new Windows kernel memory disclosure vulnerability in the creation and copying of a CONTEXT stru...
Background:
LdThis instructions' value type is assumed to be "Object". Since "this" can be other objects like an array, it has to...
This is similar to the previous issues 1457, 1459 (MSRC 42551, MSRC 42552).
This is simillar to the previous issue 1457. But this time, we use Array.prototype.reverse.
If a native array is used as a prototype, it is converted to a Var array by the Js::JavascriptNativeFloatArray::SetIs...
Here's a snippet of ExecuteImplicitCall which is responsible for updating the ImplicitCallFlags flag.
Let's consider the following example code.
It seems this is the patch for the bug.
# Exploit Title: Objdump - Integer Overflow Crash POC
[+] Credits: hyp3rlinx
[+] Credits: hyp3rlinx
## CVE-2015-5112