
CVE-2025-5548
Security research and reproduction of CVE-2025-5548: A stack-based buffer overflow in FreeFloat FTP Server 1.0. Includes binary analysis, crash…

Security research and reproduction of CVE-2025-5548: A stack-based buffer overflow in FreeFloat FTP Server 1.0. Includes binary analysis, crash…

Reproduction and root cause analysis of CVE-2024-35333, a stack buffer overflow in html2xhtml 1.3, with ASan crash output and code-level mitigation…

Proof-of-concept exploit for CVE-2025-11579, a denial-of-service vulnerability in rardecode that triggers an out-of-memory crash via a crafted RAR…

Proof-of-concept exploit for CVE-2026-8461, generating a crafted AVI file that triggers a crash in unpatched ffmpeg versions.

Proof-of-concept for CVE-2025-62454 that triggers a Windows kernel crash (BSOD) in cldflt.sys via a crafted FSCTL request, causing a page fault in…

The materials of "Hypervisor 101 in Rust", a one-day long course, to quickly learn hardware-assisted virtualization technology and its application…

Proof-of-concept exploit for CVE-2023-4863, a heap buffer overflow in libwebp, demonstrating crash trigger and reproduction steps with…

Proof-of-concept for CVE-2026-62958: crafts a malformed ELF to trigger an out-of-bounds read in Libriscv and crash the sandbox with SIGSEGV.

Proof-of-concept for CVE-2026-9256, a heap buffer overflow in NGINX's ngx_http_rewrite_module. Demonstrates worker crash and denial of service via…

Proof-of-concept exploit for CVE-2026-3909, a Chromium Skia out-of-bounds vulnerability, with patches and crash analysis for reliable triggering in…

Coverage-guided in-process fuzzer for iOS Bluetooth daemon (bluetoothd) using FRIDA, with over-the-air fuzzing for MagicPairing protocol and crash…

Proof-of-concept exploit for CVE-2026-24688, a denial-of-service vulnerability in pypdf's outline parsing. Includes malicious PDF generator and…

PoC exploit for CVE-2025-5688: remote out-of-bounds write in FreeRTOS-Plus-TCP via crafted LLMNR/mDNS queries, causing crash or potential RCE on…

Crash-only PoC for CVE-2025-69420 demonstrating a type-confusion vulnerability in OpenSSL's TimeStamp Response verification via malformed ESS…

Reproducible CVE-2026-36834 proof-of-concept demonstrating an out-of-bounds array read in LibRaw's Panasonic RW2 decoder, with mutation script and…

Proof-of-concept exploit for CVE-2025-50420 demonstrating infinite recursion in Poppler's pdfseparate via crafted /Annots dictionaries, causing…

This POC exploits a format validation vulnerability in the RTSP service of the Hipcam RealServer/V1.0, inducing a crash for approximately 45 seconds…