dos
dos 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Service
## Advisory Information
Google Android – ‘rkp_set_init_page_ro’ RKP Memory Corruption
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=984
Microsoft Windows 10 – SMBv3 Tree Connect (PoC)
# Full Proof of Concept:
QNAP NVR/NAS Devices – Buffer Overflow (PoC)
Device Model: QNAP VioStor NVR, QNAP NAS, Fujitsu Celvin NAS (May be additional re-branded)
Google Android – RKP Information Disclosure via s2-remapping Physical Ranges
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=982
Google Android – Unprotected MSRs in EL1 RKP Privilege Escalation
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=980
Google Android – ‘cfp_ropp_new_key_reenc’ / ‘cfp_ropp_new_key’ RKP Memory Corruption
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=979
OpenSSL 1.1.0 – Remote Client Denial of Service
// Source: https://guidovranken.wordpress.com/2017/01/26/cve-2017-3730-openssl-1-1-0-remote-client-denial-of-service-...
Apple macOS 10.12.1 / iOS Kernel – ‘host_self_trap’ Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1034
Apple macOS 10.12.1 / iOS Kernel – ‘IOService::matchPassive’ Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=973
Apple macOS 10.12.1 / iOS 10.2 – Kernel Userspace Pointer Memory Corruption
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1004
Google Android – ‘pm_qos’ KASLR Bypass
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=971
SunOS 5.11 ICMP – Denial of Service
#include
Mozilla Firefox < 50.1.0 - Use-After-Free
Firefox < 50.1.0 Use After Free (CVE-2016-9899)
Boxoft Wav 1.0 – Buffer Overflow
Document Title:
Adobe Flash Player 24.0.0.186 – ‘ActionGetURL2’ Out-of-Bounds Memory Corruption (2)
Source: https://cosig.gouv.qc.ca/en/cosig-2017-01-en/
Adobe Flash Player 24.0.0.186 – ‘ActionGetURL2’ Out-of-Bounds Memory Corruption (1)
Source: https://cosig.gouv.qc.ca/en/cosig-2017-01-en/
DirectAdmin 1.50.1 – Denial of Service
#################################
Brave Browser 1.2.16/1.9.56 – Address Bar URL Spoofing
Brave Browser Suffers from Address Bar Spoofing Vulnerability. Address Bar
Google Android max86902 Driver – ‘sysfs’ Interfaces Race Condition
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=963
QNAP NAS Devices – Heap Overflow
==================
SapLPD 7.40 – Denial of Service
# Exploit Title: SAPlpd 7.40 Denial of Service
FTPShell Server 6.36 – ‘.csv’ Local Denial of Service
#Exploit FTPShell server 6.36 '.csv' Crash(PoC)
Apple macOS 10.12.1 / iOS < 10.2 - syslogd Arbitrary Port Replacement
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=977
Apple macOS 10.12.1 / iOS < 10.2 - powerd Arbitrary Port Replacement
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=976
Apple macOS < 10.12.2 / iOS < 10.2 Kernel - ipc_port_t Reference Count Leak Due to Incorrect externalMethod Overrides Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=926
Apple macOS 10.12 – Double vm_deallocate in Userspace MIG Code Use-After-Free
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=954
Apple macOS 10.12.1 Kernel – Writable Privileged IOKit Registry Properties Code Execution
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=974
Google Android – WifiNative::setHotlist Stack Overflow
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=958
Horos 2.1.0 DICOM Medical Image Viewer – Denial of Service
#!/usr/bin/env python
DCMTK 3.6.0 storescp – Stack Buffer Overflow
#!/usr/bin/env python
ConQuest DICOM Server 1.4.17d – Stack Buffer (PoC)
#!/usr/bin/env python
OsiriX DICOM Viewer 8.0.1 – Memory Corruption
#!/usr/bin/env python
Orthanc DICOM Server 1.1.0 – Memory Corruption
#!/usr/bin/env python