
CVE-2024-35333
Reproduction and root cause analysis of CVE-2024-35333, a stack buffer overflow in html2xhtml 1.3, with ASan crash output and code-level mitigation…

Reproduction and root cause analysis of CVE-2024-35333, a stack buffer overflow in html2xhtml 1.3, with ASan crash output and code-level mitigation…

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced…

Repository dedicated to CVE-2022-25313, a vulnerability in Expat 2.1.0, providing analysis and potential exploitation code.

Proof-of-concept exploit for CVE-2024-22640, a ReDoS vulnerability in TCPDF <=6.7.4 triggered by crafted HTML color input, with demonstration code.

Heap-buffer-overflow in Oniguruma (function fetch_interval_quantifier)

C library for VP8/VP9 video encoding and decoding, with a focus on security patching for CVE-2023-5217.

C library for parsing XML, providing stream-oriented parsing with handler registration, supporting UTF-16 encoding, and including a reference manual.

Patched libvpx codebase addressing CVE-2023-5217 with sanitizer support and cross-platform build configurations for secure VP8/VP9 encoding.

Reference implementation of Bean Validation 2.0 (JSR-380) providing annotation-driven metadata model and API for JavaBean and method validation with…

C library for parsing XML, patched for CVE-2022-25315, providing stream-oriented XML parsing with handlers for efficient document processing.


REx@Skill - Agentic Reverse Engineering eXecution Skill for binary vulnerability discovery

0-day malware detection for binaries, source & scripts (that doesn't suck)

A native APK and DEX decompiler written in Rust

.NET deobfuscator and unpacker.

Extract the managed (.NET) assemblies out of a MAUI Android assembly store.

An LLM-driven fuzzing pipeline powered by the GitHub Security Lab Taskflow Agent