Microsoft Visio 2016 16.0.4738.1000 – ‘Log in accounts’ Denial of Service
# -⋆- coding: utf-8 -⋆-
dos 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
# -⋆- coding: utf-8 -⋆-
A bug in IonMonkeys type inference system when JIT compiling and entering a constructor function via on-stack replace...
# Exploit Title: Microsoft Windows Win32k CVE-2019-0808 Local Privilege Escalation Vulnerability
snap uses a seccomp filter to prevent the use of the TIOCSTI ioctl; in the
## Exploit Title: Canarytokens 2019-03-01 - Detection Bypass
There's a comment in FileSystemOperationRunner::BeginOperation
MidiManagerWin uses a similar instance_id mechanism to the TaskService implementation to ensure that delayed tasks ar...
Attached is a PoC file that bypasses Flash click2play in Microsoft Edge. This was tested on Windows 10 64bit v 1809 w...
There appears to be a race condition in the destruction of the ExtensionsGuestViewMessageFilter if the ProcessIdToFil...
There's a race condition in the destruction of the BindingState for bindings to the StoragePartitionService.
When libseccomp compiles filters for 64-bit systems, it needs to split 64-bit
# Exploit Title: WinAVI iPod/3GP/MP4/PSP Converter 4.4.2 Local Dos Exploit
# Exploit Title: WinMPG Video Convert Local Dos Exploit
# Exploit Title: CoreFTP Server FTP / SFTP Server v2 - Build 674 SIZE Directory Traversal
# Exploit Title: CoreFTP Server FTP / SFTP Server v2 - Build 674 MDTM Directory Traversal
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: Core FTP 2.0 build 653 - 'PBSZ' - Unauthenticated - Denial of Service (PoC)
We already reported four bugs in Android that are caused by the use of
The following bug report solely looks at the situation on the upstream master
By following the codepath that Andrea Arcangeli pointed out in his mails
# Exploit Title: FileZilla 3.40.0 - "Local search" Denial of Service (PoC)
XNU has various interfaces that permit creating copy-on-write copies of data
commit cc2d58634e0f ("netfilter: nf_nat_snmp_basic: use asn1 decoder library",
Through fuzzing of network capture .pcap files, we have identified 16 crashes with unique stack traces in tcpdump. Th...
There's a use-after-free in the implementation of the FileWriter component of the mojo bindings for the filesystem API.
There's an object-lifetime issue in the browser process in the handling of P2PSocketDispatcherHost binding in paralle...
There's a race-condition / object-lifetime issue in the browser process when the browser process shutdown races again...
There are several object-lifetime issues in the browser process in the
# -*- coding: utf-8 -*-
#Exploit Title: Buffer overflow
#!/usr/bin/env python
# Exploit Title: Xlight 3.9.1 FTP Server SEH Overwrite
https://github.com/WebKit/webkit/blob/3fff8c40c665a09de5e3ede46fc35908f69353c3/Source/JavaScriptCore/runtime/Lookup.h...
#!/usr/bin/python
#!/usr/bin/python
# -*- coding: utf-8 -*-
I happened to notice that a public X.509 certificate testcase for CVE-2014-1569 caused a stack buffer overflow in Mat...
The seccomp.2 manpage (http://man7.org/linux/man-pages/man2/seccomp.2.html) documents:
There is a memory corruption issue that occurs when processing a malformed RTP video stream in FaceTime. It appears t...
# Exploit Title: WinRAR 5.61 - Denial of Service
#Exploit Title: FTPShell Server 6.83 - Denial of Service (PoC)
#Exploit Title: BulletProof FTP Server 2019.0.0.50 - Denial of Service (PoC)
#Exploit Title: Valentina Studio 9.0.4 - Denial of Service (PoC)
#Exploit Title: NetSetMan 4.7.1 'Workgroup' - Denial of Service (PoC)