Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-17026-Exploit — An exploit for CVE-2019-17026. It pops xcalc and was tested on Ubuntu (x64). | Kitploit
Tools/GitHubGitHub/maxpl0it/cve-2019-17026-exploit
Payload GenerationVulnerability AnalysisExploitationShellcodeBinary Exploitation
GitHubmaxpl0it/cve-2019-17026-exploit

CVE-2019-17026-Exploit

An exploit for CVE-2019-17026. It pops xcalc and was tested on Ubuntu (x64).

View Repository
47165 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-17026 - A Firefox JIT bug

  • Original bug caught in the wild by Qihoo 360.
  • Exploit written by maxpl0it.
  • Works on Firefox < 72.0.1

This is an exploit for CVE-2190-17026: IonMonkey type confusion with StoreElementHole and FallibleStoreElement

This exploit does not use a sandbox escape, so for testing the security.sandbox.content.level attribute in about:config needs to be set to 0. It should be possible to chain this with CVE-2020-0674 via PAC to get a sandbox escape on Windows.

The writeup for this vulnerability and the steps taken to exploit it can be found here.

Download Tool