1253 | Advanced Inter-Process Desynchronization in SAP’s HTTP Server |
Memory corruption
RCE
HTTP Request Smuggling
Web cache poisoning
Desync attack |
SAP |
Martin Doyhenard (@tincho_508) |
Bug Bounty | 2022-08-10 | 2023-06-13 |
1247 | Attacking Titan M with Only One Byte |
Memory corruption
Local Privilege Escalation |
Google |
Damiano Melotti (@DamianoMelotti) |
Bug Bounty | 2022-08-11 | 2023-06-13 |
1240 | Researching Xiaomi’s TEE to get to Chinese money |
Payment bypass
Android
Memory corruption |
Xiaomi |
Slava Makkaveev |
Bug Bounty | 2022-08-12 | 2023-06-13 |
1222 | 1day to 0day(CVE-2022-30024) on TP-Link TL-WR841N |
Memory corruption |
TP-Link |
Trần Minh Cường |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1218 | CVE-2022-30211: Windows L2TP VPN Memory Leak and Use after Free Vulnerability |
Memory corruption
RCE |
Microsoft |
Alex Nichols (@i4mchr00t) |
Bug Bounty | 2022-08-15 | 2023-06-13 |
1216 | FreeBSD 11.0-13.0 LPE via aio_aqueue Kernel Refcount Bug |
Memory corruption
Local Privilege Escalation |
FreeBSD Security Team |
Chris (@accessvector) |
Bug Bounty | 2022-08-16 | 2023-06-13 |
1200 | Uncovering a ChromeOS remote memory corruption vulnerability |
Memory corruption |
Google |
Microsoft 365 Defender Research Team |
Bug Bounty | 2022-08-19 | 2023-06-13 |
1188 | Paracosme - CVE-2022-33318 - Remote Code Execution in ICONICS Genesis64 |
Memory corruption
RCE |
ICONICS |
Axel Souchet (@0vercl0k) |
Bug Bounty | 2022-08-22 | 2023-06-13 |
1179 | Crashing Industrial Control Systems at Pwn2Own Miami 2022 |
DoS
Memory corruption
RCE |
Unified Automation |
JFrog Security Research Team (@JFrogSecurity) |
Bug Bounty | 2022-08-25 | 2023-06-13 |
1178 | SATisfying our way into remote code execution in the OPC UA industrial stack |
Memory corruption
RCE |
Unified Automation |
JFrog Security Research Team (@JFrogSecurity) |
Bug Bounty | 2022-08-25 | 2023-06-13 |
1160 | Blind Exploits To Rule Watchguard Firewalls |
XPath injection
Memory corruption
Local Privilege Escalation
RCE |
WatchGuard |
Charles Fol (@cfreal_) |
Bug Bounty | 2022-08-29 | 2023-06-13 |
1157 | CVE-2021-38297 – Analysis of a Go Web Assembly vulnerability |
Memory corruption |
NA |
Uriya Yavnieli (@uriya_yavniely) |
Bug Bounty | 2022-08-30 | 2023-06-13 |
1146 | SETTLERS OF NETLINK: Exploiting a limited UAF in nf_tables (CVE-2022-32250) |
Memory corruption
Local Privilege Escalation |
Ubuntu
Linux Kernel Organization |
Cedric Halbronn (@saidelike) |
Bug Bounty | 2022-09-01 | 2023-06-13 |
1134 | Your Amiibo’s Haunted |
Memory corruption
Buffer Overflow
DoS |
Flipper Zero |
VVX7 (@VV_X_7) |
Bug Bounty | 2022-09-05 | 2023-06-13 |
1132 | SSD Advisory – Linux CONFIG_WATCH_QUEUE LPE |
Memory corruption
Race condition
Local Privilege Escalation |
Ubuntu
Linux Kernel Organization |
- |
Bug Bounty | 2022-09-05 | 2023-06-13 |
1127 | CVE-2022-34715: More Microsoft Windows NFS V4 Remote Code Execution |
RCE
Memory corruption |
Microsoft |
Quintin Crist |
Bug Bounty | 2022-09-06 | 2023-06-13 |
1109 | Step-by-Step Walkthrough of CVE-2022-32792 - WebKit B3ReduceStrength Out-of-Bounds Write |
Memory corruption
Browser hacking
Out-of-bounds Write |
Apple |
Daniel Lim (@daniellimws) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1108 | Binarly Finds Six High Severity Firmware Vulnerabilities In HP Enterprise Devices |
Memory corruption |
HP |
Binarly efiXplorer Team |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1107 | Baxter SIGMA Spectrum Infusion Pumps: Multiple Vulnerabilities (FIXED) |
Hardcoded credentials
Memory corruption
MiTM
Information disclosure |
Baxter Healthcare |
Deral Heiland (@Percent_X) |
Bug Bounty | 2022-09-08 | 2023-06-13 |
1085 | Colorful Vulnerabilities |
Memory corruption
Buffer Overflow |
OpenRazer |
Tal Lossos (@TalLossos) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1084 | mast1c0re: Hacking the PS4 / PS5 through the PS2 Emulator - Part 1 - Escape |
Memory corruption |
PlayStation |
CTurt (@CTurtE) |
Bug Bounty | 2022-09-26 | 2023-06-13 |
1083 | Attacking the Android kernel using the Qualcomm TrustZone |
Memory corruption |
Qalcomm
Google |
Tamir Zahavi-Brunner (@tamir_zb) |
Bug Bounty | 2022-09-14 | 2023-06-13 |
1065 | SSD Advisory – Linux CLOCK_THREAD_CPUTIME_ID LPE |
Memory corruption
Race condition
Kernel hacking |
Linux Kernel Organization |
- |
Bug Bounty | 2022-09-20 | 2023-06-13 |
1020 | Apple CoreText - An Unexpected Journey to Learn about Failure |
Memory corruption |
Apple |
Daniel Lim Wee Soong (@daniellimws) |
Bug Bounty | 2022-09-29 | 2023-06-13 |
1001 | Hacking TMNF: Part 1 - Fuzzing the game server |
RCE
Memory corruption
Format string vulnerability |
Ubisoft |
- |
Bug Bounty | 2022-10-05 | 2023-06-13 |