The Wayback Machine - https://web.archive.org/web/20210201064518/https://github.com/lockedbyte/CVE-Exploits
Skip to content
master
Go to file
Code

Files

Permalink
Failed to load latest commit information.
Type
Name
Latest commit message
Commit time
-
Jan 28, 2021
Jan 30, 2021
-
Jan 28, 2021
-
Jan 30, 2021

README.md

CVE Exploit PoCs

Some PoCs for public CVEs I have been working on.

Current exploits

  • CVE-2019-18634: Stack-based buffer overflow in sudo tgetpass.c when pwfeedback module is enabled
  • CVE-2021-3156: Heap-based buffer overflow in sudo sudoers.c when an argv ends with backslash character.
  • jad OOB write: JAD out-of-bounds write leading to code execution (No CVE given yet)