409 | The code that wasn’t there: Reading memory on an Android device by accident |
Kernel hacking
Android
Memory leak
Memory corruption |
Qualcomm |
Man Yue Mo (@mmolgtm) |
Bug Bounty | 2023-02-23 | 2023-06-13 |
365 | Hacking the Nintendo DSi Browser |
Memory corruption
Use-After-Free
Browser hacking |
Nintendo |
Nathan Farlow (@0x1337cafe) |
Bug Bounty | 2023-03-02 | 2023-06-13 |
351 | Microsoft Word RTF Font Table Heap Corruption |
Memory corruption |
Microsoft (Office) |
Joshua J. Drake (@jduck) |
Bug Bounty | 2023-03-05 | 2023-06-13 |
304 | Vulnerabilities in the TPM 2.0 reference implementation code |
Memory corruption
Out-of-bounds Read
Out-of-bounds Write |
Microsoft
VMware
Google
IBM
Lenovo
Qemu
Nuvoton
Trusted Computing Group
STMicroelectronics
Aruba Networks
CERT/CC
libtpms |
Francisco Falcon (@fdfalcon) |
Bug Bounty | 2023-03-14 | 2023-06-13 |
303 | Producing a POC for CVE-2022-42475 (Fortinet RCE) |
Memory corruption
RCE
Integer overflow
Heap overflow |
Fortinet |
Alain Mowat (@plopz0r) |
Bug Bounty | 2023-03-14 | 2023-06-13 |
221 | Escaping Adobe Sandbox: Exploiting an Integer Overflow in Microsoft Windows Crypto Provider |
Integer overflow
Memory corruption |
Microsoft |
Michele Campa (@s1ckb017) |
Bug Bounty | 2023-04-06 | 2023-06-13 |
209 | Shell in the Ghost: Ghostscript CVE-2023-28879 writeup |
Buffer Overflow
Memory corruption
RCE |
Ghostscript |
sigabrt9 (@sigabrt9) |
Bug Bounty | 2023-04-11 | 2023-06-13 |
176 | CVE-2022-29844: A Classic Buffer Overflow On The Western Digital My Cloud Pro Series PR4100 |
Buffer Overflow
Memory corruption
RCE |
Western Digital |
Luca Moro (@johncool__) |
Bug Bounty | 2023-04-20 | 2023-06-13 |
173 | The Fuzzing Guide to the Galaxy: An Attempt with Android System Services |
Android
Fuzzing
Heap overflow
Integer overflow
Out-of-bounds Write
Memory corruption
Local Privilege Escalation |
Samsung |
Anthony Remy |
Bug Bounty | 2023-04-20 | 2023-06-13 |
165 | Compromising Garmin’s Sport Watches: A Deep Dive into GarminOS and its MonkeyC Virtual Machine |
IoT
Memory corruption
Buffer Overflow
Integer overflow
Out-of-bounds Read
Out-of-bounds Write
Type confusion
Permission bypass
Reverse engineering |
Garmin |
Tao Sauvage |
Bug Bounty | 2023-04-21 | 2023-06-13 |
134 | CVE-2023-28231: RCE In The Microsoft Windows DHCPv6 Service |
RCE
Buffer Overflow
Memory corruption |
Microsoft (Windows) |
Guy Lederfein (@glederfein) |
Bug Bounty | 2023-05-02 | 2023-06-13 |
127 | The Art of Information Disclosure: A Deep Dive into CVE-2022-37985, a Unique Information Disclosure Vulnerability in Windows Graphics Component |
Out-of-bounds Read
Memory corruption |
Microsoft (Windows) |
Bing Sun |
Bug Bounty | 2023-05-03 | 2023-06-13 |
98 | The Printer Goes Brrrrr, Again! |
Printer hacking
Buffer Overflow
Memory corruption |
Canon |
Rémi Jullian (@netsecurity1) |
Bug Bounty | 2023-05-12 | 2023-06-13 |
96 | CS:GO: From Zero to 0-day |
Game hacking
RCE
Memory corruption
Arbitrary file download
Arbitrary file write
DLL Hijacking
Privilege Escalation |
Valve (CS:GO) |
Felipe |
Bug Bounty | 2023-05-13 | 2023-06-13 |
88 | FriendlyName’ Buffer Overflow Vulnerability in Wemo Smart Plug V2 |
IoT
Buffer Overflow
Memory corruption
Reverse engineering |
Belkin (Wemo) |
Amit Serper (@0xAmit) |
Bug Bounty | 2023-05-16 | 2023-06-13 |
74 | Blind OS Command Injection via Activation Request |
Memory corruption
Buffer Overflow
Out-of-bounds Read |
VMware |
Nguyễn Hoàng Thạch (@hi_im_d4rkn3ss) |
Bug Bounty | 2023-05-18 | 2023-06-13 |
53 | Exploiting The Sonos One Speaker Three Different Ways: A Pwn2Own Toronto Highlight |
Memory corruption
RCE
Out-of-bounds Read |
Sonos |
The ZDI Research Team (@thezdi) |
Bug Bounty | 2023-05-25 | 2023-06-13 |
52 | Exploring Three Remote Code Execution Vulnerabilities in RPC Runtime |
RCE
MS-RPC
Integer overflow
Memory corruption |
Microsoft (Windows) |
Ben Barnea (@nachoskrnl) |
Bug Bounty | 2023-05-26 | 2023-06-13 |
37 | Anatomy of an IoT Exploit, from Hands-On to RCE |
IoT
RCE
Buffer Overflow
Memory corruption |
Wavlink |
David Baker |
Bug Bounty | 2023-06-01 | 2023-06-13 |