<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Aslr-Bypass — PoC Archive</title><link>https://poc.intelseclab.com/tags/aslr-bypass/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/aslr-bypass/index.xml" rel="self" type="application/rss+xml"/><item><title>nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-42533-nginx-pcre-heap-overflow-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-42533-nginx-pcre-heap-overflow-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-42533. Status: Patched. Affects: nginx 1.30.1 (and likely earlier versions). Tags: nginx, pcre, heap-overflow, rce, preauth, info-leak, capture-variable, map-directive, aslr-bypass, CVE-2026-42533.</description><category>web</category><category>Critical</category><category>nginx</category><category>pcre</category><category>heap-overflow</category><category>rce</category><category>preauth</category><category>info-leak</category><category>capture-variable</category><category>map-directive</category><category>aslr-bypass</category><category>CVE-2026-42533</category></item><item><title>MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</guid><description>Critical severity (CVSS 8.8) — binary · MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet. Status: Unpatched. Affects: MariaDB Server, ST_Area() geometry function and SYS_REFCURSOR cursor-array management. Tags: mariadb, database, rce, low-privilege, heap, oob-read, use-after-free, aslr-bypass, pie-bypass, coop, vtable, cursor, st-area, multipolygon, CWE-125, CWE-416, docker, v12-security.</description><category>binary</category><category>Critical</category><category>mariadb</category><category>database</category><category>rce</category><category>low-privilege</category><category>heap</category><category>oob-read</category><category>use-after-free</category><category>aslr-bypass</category><category>pie-bypass</category><category>coop</category><category>vtable</category><category>cursor</category><category>st-area</category><category>multipolygon</category><category>CWE-125</category><category>CWE-416</category><category>docker</category><category>v12-security</category></item><item><title>GitLab Notebook-Diff Oj Parser Memory-Corruption Chain → Unauthenticated-Reach RCE (No CVE Yet)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_gitlab-oj-json-parser-rce-chain/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_gitlab-oj-json-parser-rce-chain/</guid><description>Critical severity — web · N/A (no CVE assigned as of 2026-07-27 — researcher disclosure via depthfirst.com blog, covered by The Hacker News). Status: Weaponized. Affects: GitLab Community/Enterprise Edition — Jupyter notebook diff rendering (backed by the Oj native Ruby JSON parser gem). Tags: gitlab, oj-gem, json-parser, rce, aslr-bypass, ruby, deserialization, no-cve-yet.</description><category>web</category><category>Critical</category><category>gitlab</category><category>oj-gem</category><category>json-parser</category><category>rce</category><category>aslr-bypass</category><category>ruby</category><category>deserialization</category><category>no-cve-yet</category></item><item><title>PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2005-postgresql-pgcrypto-heapoverflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2005-postgresql-pgcrypto-heapoverflow/</guid><description>Critical severity — binary · CVE-2026-2005. Status: PoC. Affects: PostgreSQL pgcrypto extension (PGP session-key parsing). Tags: postgresql, pgcrypto, heap-overflow, aslr-bypass, privilege-escalation, pgp, memory-corruption.</description><category>binary</category><category>Critical</category><category>postgresql</category><category>pgcrypto</category><category>heap-overflow</category><category>aslr-bypass</category><category>privilege-escalation</category><category>pgp</category><category>memory-corruption</category></item><item><title>nginx PoolSlip × Rift Chained ASLR-Independent Remote Code Execution (CVE-2026-9256 / CVE-2026-42945)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-9256-nginx-poolslip-rift-rce-chain/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-9256-nginx-poolslip-rift-rce-chain/</guid><description>Critical severity — web · CVE-2026-9256 ("PoolSlip"), chained with CVE-2026-42945 ("rift"). Status: PoC. Affects: nginx (rewrite engine). Tags: nginx, heap-overflow, heap-over-read, aslr-bypass, rce, rewrite-engine, request-smuggling-adjacent, chained-exploit.</description><category>web</category><category>Critical</category><category>nginx</category><category>heap-overflow</category><category>heap-over-read</category><category>aslr-bypass</category><category>rce</category><category>rewrite-engine</category><category>request-smuggling-adjacent</category><category>chained-exploit</category></item><item><title>objdump DLX ELF Backend Out-of-Bounds Write (Crash-to-Calc)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_objdump-dlx-elf-backend-oob/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_objdump-dlx-elf-backend-oob/</guid><description>Medium severity — binary · None assigned as of 2026-07-03. Status: PoC. Affects: GNU Binutils objdump — DLX ELF backend (elf32-dlx). Tags: binutils, objdump, elf-parsing, dlx, out-of-bounds-write, aslr-bypass, local-code-execution, crash-to-calc.</description><category>binary</category><category>Medium</category><category>binutils</category><category>objdump</category><category>elf-parsing</category><category>dlx</category><category>out-of-bounds-write</category><category>aslr-bypass</category><category>local-code-execution</category><category>crash-to-calc</category></item></channel></rss>