iMessage – Memory Corruption when Decoding NSKnownKeysDictionary1
There is a memory corruption vulnerability when decoding an object of class NSKnownKeysDictionary1. This class decod...
dos 相关类别内容索引。Exploit Database / Exploits for Penetration Testers, Researchers, and Ethical Hackers。聚合漏洞利用代码、PoC 与研究资料。
There is a memory corruption vulnerability when decoding an object of class NSKnownKeysDictionary1. This class decod...
When deserializing a class with initWithCoder, subclasses of that class can also be deserialized so long as they do n...
While fuzzing JSC, I encountered the following JS program which crashes JSC from current HEAD and release (/System/Li...
While fuzzing JavaScriptCore, I encountered the following (modified and commented) JavaScript program which crashes j...
When deserializing NSObjects with the NSArchiver API [1], one can supply a whitelist of classes that are allowed to b...
# Exploit Title: pdfresurrect 0.15 Buffer Overflow
The digital touch iMessage extension can read out of bounds if a malformed Tap message contains a color array that is...
# Exploit Title: BACnet Stack 0.8.6 - Denial of Service
# Exploit Title: WinMPG iPod Convert 3.0 - 'Register' Denial of Service
[+] Credits: John Page (aka hyp3rlinx)
# Exploit Title: Bluekeep Denial of Service (metasploit module)
CVE-2019-2107 - looks scary. Still remember Stagefright and PNG bugs vulns .... With CVE-2019-2107 the decoder/codec ...
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
-----=====[ Background ]=====-----
----=====[ Background ]=====-----
For constructors, Spidermonkey implements a "definite property analysis" [1] to compute which properties will definit...
-----=====[ Background ]=====-----
Loading please wait
The following program (found through fuzzing and manually modified) crashes Spidermonkey built from the current beta ...
Windows: Windows Font Cache Service Insecure Sections EoP
Windows: CmpAddRemoveContainerToCLFSLog Arbitrary File/Directory Creation EoP
# Exploit Title: GSearch v1.0.1.0 - Denial of Service (PoC)
When a #BR exception is raised because of an MPX bounds violation, Linux parses
X41 D-Sec GmbH Security Advisory: X41-2019-003
X41 D-Sec GmbH Security Advisory: X41-2019-002
X41 D-Sec GmbH Security Advisory: X41-2019-001
-----BEGIN PGP SIGNED MESSAGE-----
# Exploit Author: Juan Sacco - http://exploitpack.com
[+] Credits: John Page (aka hyp3rlinx)
import socket, sys, struct
The following issue exists in the android-msm-wahoo-4.4-pie branch of
While fuzzing Spidermonkey, I encountered the following (commented and modified) JavaScript program which crashes deb...