
gdcm-security-poc
Private end-to-end sanitizer reproduction package for six GDCM findings

Private end-to-end sanitizer reproduction package for six GDCM findings

In-depth analysis and proof-of-concept for CVE-2026-27280, an out-of-bounds write in Adobe DNG SDK's dng_render_task::ProcessArea, reachable via…

A benchmark for LLM-driven bug discovery: 77 challenges across 43 open-source projects (C/C++/Java).

Proof-of-concept exploit for CVE-2025-46819, a Redis Lua long-string delimiter out-of-bounds read, demonstrating a crash via malformed input.

Systematic reverse engineering of Cisco ASA's lina binary to discover and analyze memory corruption vulnerabilities, including CVE-2025-20333 and…

Instrumented fuzzer for PLC-based ICS control applications, targeting Codesys runtime on Wago controllers to uncover memory corruption and…

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

Runtime instrumentation framework for building dynamic analysis tools: tracing, profiling, code coverage, memory debugging, fuzzing, and disassembly…

Collections of my POCs for android vendor CVEs

Fuzzes CPU implementations by generating test inputs from software proxies, then executes them on real hardware to detect microarchitecture defects…

AArch64 fuzzer based on the Apple Silicon hypervisor

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application…

Automated HTTP Request Repeating With Burp Suite

Multi-architecture pcode emulator using Ghidra/Sleigh for AFL++ fuzzing of binaries, firmware, and embedded targets; detects memory-corruption bugs…

A coverage-guided REST API fuzzer developed on top of LibAFL


A BASH Script to automate the installation of the most popular bug bounty tools