Transmission – Integer Overflows Parsing Torrent Files
I took a look at torrent file parsing in libtransmission, there are a few integer overflows because the tr_new/tr_new...
dos 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
I took a look at torrent file parsing in libtransmission, there are a few integer overflows because the tr_new/tr_new...
# Exploit title: Wavpack 5.1.0 - Denial of Service
We have discovered a new Windows kernel memory disclosure vulnerability in the creation and copying of a CONTEXT stru...
# Exploit Title: Aastra 6755i SIP SP4 | Unauthorized Remote Reboot
# Exploit Title: Siemens SIPROTEC 4 and SIPROTEC Compact EN100 Ethernet Module < V4.25 - Denial of Service
# Exploit Title: Exploit Denial of Service JBoss Remoting (4447/9999)
Background:
Here's a snippet of the method.
Related to issue 1490 .
This vulnerability relies on several minor oversights in the handling of shading patterns in pdfium, I'll try to deta...
LdThis instructions' value type is assumed to be "Object". Since "this" can be other objects like an array, it has to...
This is similar to the previous issues 1457, 1459 (MSRC 42551, MSRC 42552).
This is simillar to the previous issue 1457. But this time, we use Array.prototype.reverse.
If a native array is used as a prototype, it is converted to a Var array by the Js::JavascriptNativeFloatArray::SetIs...
Here's a snippet of ExecuteImplicitCall which is responsible for updating the ImplicitCallFlags flag.
Let's consider the following example code.
It seems this is the patch for the bug.
# Exploit Title: Objdump - Integer Overflow Crash POC
AppleEmbeddedOSSupportHost.kext is presumably involved in the communication with the OS running on the touch bar on n...
The keystore binder service ("android.security.IKeystoreService") allows users to issue several commands related to k...
# Exploit Author: Juan Sacco - http://exploitpack.com
Claymore’s Dual GPU Miner 10.5 and below is vulnerable to a format strings vulnerability. This allows an unauthentica...
# EDB Note: python doser.py -g 'http://localhost/wp-admin/load-scripts.php?c=1&load%5B%5D=eutil,common,wp-a11y,sack,q...
#!/usr/bin/python
The sysctls vfs.generic.conf.* are handled by sysctl_vfs_generic_conf(), which is implemented as follows:
# Exploit Title: DoS caused by the interactive call between two functions
#!/usr/bin/python
# Exploit Title: phpFreeChat 1.7 and earlier - Denial of Service
AppleIntelCapriController::getDisplayPipeCapability reads an attacker-controlled dword value from a userclient structure
#!/usr/bin/python3
If variables don't escape the scope, the variables can be allocated to the stack. However, there are some situations,...
AsmJSByteCodeGenerator::EmitCall which is used to emit call insturctions doesn't check if an array identifier is used...
// Here's the PoC demonstrating OOB write.
Since the PoC is only triggerable when the "DeferParse" flag enabled and requires a with statement, I think this is s...
Here's a snippet of the method.
Let's start with comments in the "GlobOpt::TrackIntSpecializedAddSubConstant" method.
author = '''
=============================================
Document Title:
Here's a snippet of AppendLeftOverItemsFromEndSegment in JavascriptArray.inl.
Windows: SMB Server (v1 and v2) Mount Point Arbitrary Device Open EoP
Windows: NtImpersonateAnonymousToken LPAC to Non-LPAC EoP