5211 | CVE-2014-7216: A Journey Through Yahoo’s Bug Bounty Program |
Buffer Overflow
Memory corruption |
Yahoo! / Verizon Media |
Julien Ahrens (@MrTuxracer) |
Bug Bounty | 2015-09-03 | 2023-06-13 |
5156 | How we broke PHP, hacked Pornhub and earned $20,000 |
RCE
Memory corruption
Use-After-Free |
PornHub |
Ruslan Habalov (@evonide) |
Bug Bounty | 2016-07-23 | 2023-06-13 |
4833 | CVE-2017-13253: Buffer overflow in multiple Android DRM services |
Memory corruption
Local Privilege Escalation |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-03-15 | 2023-06-13 |
4506 | CVE-2018-9411: New critical vulnerability in multiple high-privileged Android services |
Memory corruption |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-10-30 | 2023-06-13 |
4485 | CVE-2018-9539: Use-after-free vulnerability in privileged Android service |
Memory corruption
Use-After-Free |
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2018-11-09 | 2023-06-13 |
4241 | Facebook Fizz integer overflow vulnerability (CVE-2019-3560) |
Integer overflow
Memory corruption |
Meta / Facebook |
Kevin Backhouse (@kevin_backhouse) |
Bug Bounty | 2019-03-19 | 2023-06-13 |
4196 | Banner Grabbing to DoS and Memory Corruption |
DoS
Information disclosure |
NA |
Daniel V. (@d4niel_v) |
Bug Bounty | 2019-04-16 | 2023-06-13 |
4170 | Don’t Follow The Masses: Bug Hunting in JavaScript Engines |
Buffer Overflow
Memory corruption |
Google |
Dimitri Fourny (@dimitrifourny) |
Bug Bounty | 2019-04-29 | 2023-06-13 |
3892 | How a double-free bug in WhatsApp turns to RCE |
Memory corruption
RCE
Android |
Meta / Facebook |
Awakened |
Bug Bounty | 2019-10-02 | 2023-06-13 |
3853 | Filling in the Blanks: Exploiting Null Byte Buffer Overflow for a $40,000 Bounty |
Null byte buffer overflow
Memory corruption |
NA |
Sam Curry (@samwcyo) |
Bug Bounty | 2019-11-01 | 2023-06-13 |
3798 | Google Chrome portal element fuzzing |
RCE
Memory corruption
Buffer Overflow
Use-After-Free |
Google |
Pawel Wylecial (@h0wlu) |
Bug Bounty | 2019-12-06 | 2023-06-13 |
3739 | Exploiting Wi-Fi Stack on Tesla Model S |
Wifi hacking
Driver hacking
RCE
Memory corruption |
Tesla |
Tencent Keen Security Lab |
Bug Bounty | 2020-01-02 | 2023-06-13 |
3730 | Google Chrome display locking fuzzing |
Use-After-Free
Memory corruption |
Google |
Pawel Wylecial (@h0wlu) |
Bug Bounty | 2020-01-08 | 2023-06-13 |
3553 | The story of a fuzzing integration reward |
Memory corruption |
Google |
Andrea Brancaleoni (@nJoyneer) |
Bug Bounty | 2020-04-08 | 2023-06-13 |
3547 | Multiple Kernel Vulnerabilities Affecting All Qualcomm Devices |
Memory corruption
Race condition |
Qalcomm
Samsung |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2020-04-15 | 2023-06-13 |
3440 | Microsoft%27s first bug |
Memory corruption
File format vulnerability |
Microsoft |
Lê Hữu Quang Linh (@linhlhq) |
Bug Bounty | 2020-05-30 | 2023-06-13 |
3138 | VMware Workstation: Attack surface through Virtual Printer |
Memory corruption
Integer overflow |
VMware |
Lê Hữu Quang Linh (@linhlhq) |
Bug Bounty | 2020-09-23 | 2023-06-13 |
2994 | An iOS zero-click radio proximity exploit odyssey |
iOS
Memory corruption
Buffer Overflow |
Apple |
Ian Beer (@i41nbeer) |
Bug Bounty | 2020-12-01 | 2023-06-13 |
2975 | Game On – Finding vulnerabilities in Valve’s “Steam Sockets” |
Memory corruption |
Valve |
Eyal Itkin (@EyalItkin) |
Bug Bounty | 2020-12-10 | 2023-06-13 |
2797 | Hunting for bugs in Telegram%27s animated stickers remote attack surface |
Memory corruption
DoS |
Telegram |
polict (@polict_) |
Bug Bounty | 2021-02-16 | 2023-06-13 |
2595 | Exploiting memory corruption vulnerabilities on Android |
Memory corruption
Android |
Paypal |
Oversecured (@OversecuredInc) |
Bug Bounty | 2021-04-30 | 2023-06-13 |
2527 | Patch Gapping a Safari Type Confusion |
Memory corruption |
Apple |
Theori (@theori_io) |
Bug Bounty | 2021-05-25 | 2023-06-13 |
2427 | CVE-2021-22555: Turning x00x00 into 10000$ |
Memory corruption
Local Privilege Escalation |
Google |
Andy Nguyen (@theflow0) |
Bug Bounty | 2021-07-07 | 2023-06-13 |
2345 | Do you like to read? I can take over your Kindle with an e-book |
Memory corruption
RCE
Local Privilege Escalation |
Amazon |
Slava Makkaveev |
Bug Bounty | 2021-08-06 | 2023-06-13 |
2304 | Zoom RCE from Pwn2Own 2021 |
RCE
Memory corruption |
Zoom |
Thijs Alkemade (@xnyhps) |
Bug Bounty | 2021-08-23 | 2023-06-13 |