<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CWE-125 — PoC Archive</title><link>https://poc.intelseclab.com/tags/cwe-125/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cwe-125/index.xml" rel="self" type="application/rss+xml"/><item><title>MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</guid><description>Critical severity (CVSS 8.8) — binary · MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet. Status: Unpatched. Affects: MariaDB Server, ST_Area() geometry function and SYS_REFCURSOR cursor-array management. Tags: mariadb, database, rce, low-privilege, heap, oob-read, use-after-free, aslr-bypass, pie-bypass, coop, vtable, cursor, st-area, multipolygon, CWE-125, CWE-416, docker, v12-security.</description><category>binary</category><category>Critical</category><category>mariadb</category><category>database</category><category>rce</category><category>low-privilege</category><category>heap</category><category>oob-read</category><category>use-after-free</category><category>aslr-bypass</category><category>pie-bypass</category><category>coop</category><category>vtable</category><category>cursor</category><category>st-area</category><category>multipolygon</category><category>CWE-125</category><category>CWE-416</category><category>docker</category><category>v12-security</category></item><item><title>LibRaw pana8.cpp GetDBit() Out-of-Bounds Array Read (CVE-2026-36834)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36834-libraw-oob-read/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36834-libraw-oob-read/</guid><description>Medium severity (CVSS 6.5) — binary · CVE-2026-36834. Status: PoC. Affects: LibRaw — src/decoders/pana8.cpp. Tags: libraw, out-of-bounds-read, rw2, huffman, image-parsing, cwe-125, cwe-129.</description><category>binary</category><category>Medium</category><category>libraw</category><category>out-of-bounds-read</category><category>rw2</category><category>huffman</category><category>image-parsing</category><category>cwe-125</category><category>cwe-129</category></item><item><title>KVM SEV-SNP Page State Change (PSC) Heap Out-of-Bounds — CVE-2026-53360</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-53360-kvm-sev-snp-psc-heap-oob/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-53360-kvm-sev-snp-psc-heap-oob/</guid><description>High severity — binary · CVE-2026-53360. Status: PoC. Affects: Linux KVM host, SEV-SNP support (arch/x86/kvm/svm/sev.c, snp_begin_psc() / setup_vmgexit_scratch()). Tags: kvm, sev-snp, kernel, heap-oob, kasan, guest-escape, slab, kmalloc-cg, linux-kernel, cwe-125, cwe-787.</description><category>binary</category><category>High</category><category>kvm</category><category>sev-snp</category><category>kernel</category><category>heap-oob</category><category>kasan</category><category>guest-escape</category><category>slab</category><category>kmalloc-cg</category><category>linux-kernel</category><category>cwe-125</category><category>cwe-787</category></item></channel></rss>