Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2022-36163 | Kitploit
Tools/GitHubGitHub/maherazzouzi/cve-2022-36163
Vulnerability AnalysisExploitationInformation GatheringFuzzingBinary Analysis
GitHubmaherazzouzi/cve-2022-36163

CVE-2022-36163

View Repository
114 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2022-36163

[Suggested description] A format string vulnerability was found in pdftoroff hovacui 1.1.0 pdf reader. A user can control the second parameter to sprintf which can lead to DoS or Information Disclosure for more attacks. sprintf(command, output->postsave, fileno, fileno);


[Additional Information] This is just a DoS PoC: *** %n in writable segment detected *** [1] 8518 IOT instruction (core dumped) python3 exploit.py


[VulnerabilityType Other] Format string vulnerability.


[Vendor of Product] pdftoroff


[Affected Product Code Base] hovacui - 1.1.0


[Affected Component] hovacui.c, line: 1572


[Attack Type] Local


[Impact Denial of Service] true


[Impact Information Disclosure] true


[Attack Vectors] Create a bogus postsave and then open a pdf file, and save it.


[Discoverer] Maher Azzouzi


[Reference] http://hovacui.com http://pdftoroff.com

Download Tool