<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dos — PoC Archive</title><link>https://poc.intelseclab.com/tags/dos/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/dos/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</guid><description>High severity (CVSS 8.4) — network · CVE-2026-54992. Status: PoC (crash/DoS confirmed, no RCE demonstrated). Affects: Windows Message Queuing (MSMQ) — Queue Manager (mqqm.dll, hosted in mqsvc.exe), reached via the MS-MQRR (RemoteRead) RPC interface. Tags: windows, msmq, message-queuing, heap-overflow, integer-overflow, rpc, dos, crash.</description><category>network</category><category>High</category><category>windows</category><category>msmq</category><category>message-queuing</category><category>heap-overflow</category><category>integer-overflow</category><category>rpc</category><category>dos</category><category>crash</category></item><item><title>XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-08_xring-xquic-qpack-ring-mem-resize-underflow/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-08_xring-xquic-qpack-ring-mem-resize-underflow/</guid><description>Critical severity — network. Status: Weaponized (public PoC, unpatched at publication). Affects: [alibaba/xquic](https://github.com/alibaba/xquic) — QUIC/HTTP-3 library, used by Tengine and reportedly across Alibaba's cloud/CDN infrastructure (Taobao, AliPay). Tags: quic, http3, qpack, xquic, alibaba, tengine, ring-buffer, integer-underflow, heap-oob-read, memcpy, remote, unauthenticated, dos, no-cve.</description><category>network</category><category>Critical</category><category>quic</category><category>http3</category><category>qpack</category><category>xquic</category><category>alibaba</category><category>tengine</category><category>ring-buffer</category><category>integer-underflow</category><category>heap-oob-read</category><category>memcpy</category><category>remote</category><category>unauthenticated</category><category>dos</category><category>no-cve</category></item><item><title>Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-29384-tenda-ac9-stack-overflow/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-29384-tenda-ac9-stack-overflow/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-29384. Status: PoC. Affects: Tenda AC9 dual-band wireless router, web management interface (/goform/AdvSetMacMtuWan endpoint). Tags: tenda, ac9, router, stack-buffer-overflow, cwe-121, dos, rce, mips, embedded, iot, python, ruby, metasploit.</description><category>network</category><category>Critical</category><category>tenda</category><category>ac9</category><category>router</category><category>stack-buffer-overflow</category><category>cwe-121</category><category>dos</category><category>rce</category><category>mips</category><category>embedded</category><category>iot</category><category>python</category><category>ruby</category><category>metasploit</category></item><item><title>Windows HTTP.sys Header-Count-Triggered Kernel Memory Corruption / BSOD (CVE-2026-49160)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</guid><description>High severity — binary · CVE-2026-49160. Status: PoC. Affects: Windows HTTP.sys kernel-mode driver (Windows 10 build 26100 confirmed in crash logs). Tags: windows, http.sys, kernel, http2, dos, bsod, memory-corruption, integer-overflow.</description><category>binary</category><category>High</category><category>windows</category><category>http.sys</category><category>kernel</category><category>http2</category><category>dos</category><category>bsod</category><category>memory-corruption</category><category>integer-overflow</category></item><item><title>VirtualBox DevVGA_VBVA Integer Overflow leading to Guest-Triggerable DoS (CVE-2026-35250)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-35250-virtualbox-vbva-integer-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-35250-virtualbox-vbva-integer-overflow/</guid><description>Low severity (CVSS 2.3) — binary · CVE-2026-35250. Status: PoC. Affects: Oracle VirtualBox — DevVGA_VBVA.cpp. Tags: virtualbox, integer-overflow, dos, vbva, guest-to-host, cwe-190, ai-assisted-research.</description><category>binary</category><category>Low</category><category>virtualbox</category><category>integer-overflow</category><category>dos</category><category>vbva</category><category>guest-to-host</category><category>cwe-190</category><category>ai-assisted-research</category></item><item><title>Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11499-tenda-router-bof/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11499-tenda-router-bof/</guid><description>High severity — network · CVE-2026-11499. Status: PoC. Affects: Tenda HG7 / HG9 / HG10 routers (firmware family HG7_HG9_HG10re_300001138_en_xpon and similar). Tags: tenda, router, buffer-overflow, cwe-121, dos, embedded, iot, rce.</description><category>network</category><category>High</category><category>tenda</category><category>router</category><category>buffer-overflow</category><category>cwe-121</category><category>dos</category><category>embedded</category><category>iot</category><category>rce</category></item><item><title>strongSwan RADIUS Attribute-Iterator Pre-Auth Infinite Loop / Remote DoS (CVE-2026-35333)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-35333-strongswan-radius-infinite-loop-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-35333-strongswan-radius-infinite-loop-dos/</guid><description>Medium severity — network · CVE-2026-35333. Status: PoC. Affects: strongSwan — libradius. Tags: strongswan, radius, dos, infinite-loop, integer-underflow, pre-auth.</description><category>network</category><category>Medium</category><category>strongswan</category><category>radius</category><category>dos</category><category>infinite-loop</category><category>integer-underflow</category><category>pre-auth</category></item><item><title>PJSIP / PJNATH ICE Session Stack Buffer Overflow via SDP ice-ufrag (CVE-2026-25994)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-25994-pjsip-ice-stack-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-25994-pjsip-ice-stack-overflow/</guid><description>High severity — network · CVE-2026-25994. Status: PoC. Affects: PJSIP / PJNATH (ICE implementation used by pjsua and SIP/VoIP stacks). Tags: pjsip, pjnath, ice, sip, voip, stack-overflow, dos, sdp, buffer-overflow.</description><category>network</category><category>High</category><category>pjsip</category><category>pjnath</category><category>ice</category><category>sip</category><category>voip</category><category>stack-overflow</category><category>dos</category><category>sdp</category><category>buffer-overflow</category></item><item><title>PgBouncer SASL Length Field Integer Overflow Crash — CVE-2026-6664</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6664-pgbouncer-integer-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6664-pgbouncer-integer-overflow/</guid><description>High severity — network · CVE-2026-6664. Status: PoC. Affects: PgBouncer (PostgreSQL connection pooler). Tags: pgbouncer, postgresql, integer-overflow, sasl, scram, dos, cwe-190.</description><category>network</category><category>High</category><category>pgbouncer</category><category>postgresql</category><category>integer-overflow</category><category>sasl</category><category>scram</category><category>dos</category><category>cwe-190</category></item><item><title>Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4350-perfmatters-file-deletion/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4350-perfmatters-file-deletion/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-4350. Status: PoC. Affects: Perfmatters WordPress plugin. Tags: wordpress, plugin, perfmatters, path-traversal, arbitrary-file-deletion, admin-ajax, dos, nuclei.</description><category>web</category><category>High</category><category>wordpress</category><category>plugin</category><category>perfmatters</category><category>path-traversal</category><category>arbitrary-file-deletion</category><category>admin-ajax</category><category>dos</category><category>nuclei</category></item><item><title>OpenBSD slaacd/rad Infinite Loop via Malformed ND Option (CVE-2026-41285)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-41285-openbsd-slaacd-nd-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-41285-openbsd-slaacd-nd-dos/</guid><description>High severity — network · CVE-2026-41285. Status: Weaponized. Affects: OpenBSD slaacd (SLAAC autoconfiguration daemon) and rad (Router Advertisement daemon). Tags: openbsd, slaacd, rad, icmpv6, ipv6, dos, infinite-loop, scapy, neighbor-discovery.</description><category>network</category><category>High</category><category>openbsd</category><category>slaacd</category><category>rad</category><category>icmpv6</category><category>ipv6</category><category>dos</category><category>infinite-loop</category><category>scapy</category><category>neighbor-discovery</category></item><item><title>Notepad++ nativeLang.xml Format String Crash / Info Disclosure — CVE-2026-3008</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3008-notepadpp-formatstring/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-3008-notepadpp-formatstring/</guid><description>Medium severity — binary · CVE-2026-3008. Status: PoC. Affects: Notepad++ 8.9.3. Tags: notepad++, format-string, wsprintfw, dos, information-disclosure, localization, windows.</description><category>binary</category><category>Medium</category><category>notepad++</category><category>format-string</category><category>wsprintfw</category><category>dos</category><category>information-disclosure</category><category>localization</category><category>windows</category></item><item><title>Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0211-nginx-quic-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0211-nginx-quic-heap-overflow/</guid><description>High severity — web · CVE-2026-0211 (repository explicitly labels this as a hypothetical/simulated CVE for coursework, not a confirmed vendor-assigned vulnerability). Status: PoC. Affects: A custom, deliberately vulnerabilized fork of Nginx 1.25.3's QUIC transport module (ngx_event_quic_transport.c), run inside a purpose-built Docker lab — not the stock upstream Nginx release. Tags: nginx, quic, http-3, heap-overflow, dos, fuzzing, dcid, academic-lab, docker.</description><category>web</category><category>High</category><category>nginx</category><category>quic</category><category>http-3</category><category>heap-overflow</category><category>dos</category><category>fuzzing</category><category>dcid</category><category>academic-lab</category><category>docker</category></item><item><title>Multer Orphaned Temporary File Disk-Exhaustion DoS — CVE-2026-3304</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3304-multer-orphaned-file-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3304-multer-orphaned-file-dos/</guid><description>High severity (CVSS 8.7) — web · CVE-2026-3304. Status: PoC. Affects: Multer (Node.js multipart/form-data middleware for Express). Tags: multer, nodejs, express, dos, file-upload, orphaned-file, disk-exhaustion, multipart.</description><category>web</category><category>High</category><category>multer</category><category>nodejs</category><category>express</category><category>dos</category><category>file-upload</category><category>orphaned-file</category><category>disk-exhaustion</category><category>multipart</category></item><item><title>MiniTool pwdrvio.sys Kernel Driver Buffer Overflow — Local DoS/BSOD (CVE-2026-36980)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36980-minitool-kernel-driver-bsod-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-36980-minitool-kernel-driver-bsod-dos/</guid><description>Medium severity — binary · CVE-2026-36980. Status: PoC. Affects: MiniTool pwdrvio.sys kernel driver. Tags: minitool, kernel-driver, ioctl, bsod, dos, pool-corruption, windows.</description><category>binary</category><category>Medium</category><category>minitool</category><category>kernel-driver</category><category>ioctl</category><category>bsod</category><category>dos</category><category>pool-corruption</category><category>windows</category></item><item><title>Django MultiPartParser Base64 Whitespace CPU Amplification DoS — CVE-2026-33033</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33033-django-multipartparser-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-33033-django-multipartparser-dos/</guid><description>Medium severity — web · CVE-2026-33033. Status: PoC. Affects: Django (django.http.multipartparser.MultiPartParser). Tags: django, dos, multipart, base64, cpu-amplification, python, file-upload.</description><category>web</category><category>Medium</category><category>django</category><category>dos</category><category>multipart</category><category>base64</category><category>cpu-amplification</category><category>python</category><category>file-upload</category></item><item><title>Casdoor Authenticated Path Traversal to Arbitrary File Write (CVE-2026-6815)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6815-casdoor-path-traversal-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6815-casdoor-path-traversal-file-write/</guid><description>High severity — web · CVE-2026-6815. Status: Weaponized. Affects: Casdoor (open-source identity/access management platform). Tags: casdoor, path-traversal, arbitrary-file-write, rce, dos, authenticated, cwe-22.</description><category>web</category><category>High</category><category>casdoor</category><category>path-traversal</category><category>arbitrary-file-write</category><category>rce</category><category>dos</category><category>authenticated</category><category>cwe-22</category></item><item><title>BIRD/BIRD2 BGP AS_PATH Mask Matching Stack Buffer Overflow (CVE-2026-49943)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49943-bird-bgp-aspath-stack-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-49943-bird-bgp-aspath-stack-overflow/</guid><description>High severity (CVSS 3.1) — network · CVE-2026-49943. Status: PoC. Affects: BIRD Internet Routing Daemon (BGP implementation). Tags: bird, bird2, bgp, as-path, stack-buffer-overflow, denial-of-service, routing, dos.</description><category>network</category><category>High</category><category>bird</category><category>bird2</category><category>bgp</category><category>as-path</category><category>stack-buffer-overflow</category><category>denial-of-service</category><category>routing</category><category>dos</category></item><item><title>Netlogon CLDAP Stack Buffer Overflow (CVE-2026-41089)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-04_netlogon-cldap-stack-buffer-overflow/</link><pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-04_netlogon-cldap-stack-buffer-overflow/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-41089. Status: Weaponized. Affects: Microsoft Windows Netlogon (Domain Controller CLDAP path). Tags: Netlogon, CLDAP, Windows Server, stack-overflow, unauthenticated, DoS, potential-RCE.</description><category>network</category><category>Critical</category><category>Netlogon</category><category>CLDAP</category><category>Windows Server</category><category>stack-overflow</category><category>unauthenticated</category><category>DoS</category><category>potential-RCE</category></item><item><title>Notepad++ &lt;= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-28_notepad-plus-plus-8-9-6-multi-cve/</link><pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-28_notepad-plus-plus-8-9-6-multi-cve/</guid><description>High severity (CVSS 5) — binary · CVE-2026-48770, CVE-2026-48778, CVE-2026-48800. Status: Patched. Affects: Notepad++. Tags: Notepad++, Windows, OOB-read, DoS, command-injection, config.xml, shortcuts.xml, local.</description><category>binary</category><category>High</category><category>Notepad++</category><category>Windows</category><category>OOB-read</category><category>DoS</category><category>command-injection</category><category>config.xml</category><category>shortcuts.xml</category><category>local</category></item><item><title>Next.js RSC Server-Action DoS via Flight Deserialization (CVE-2026-23870)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-rsc-dos-flight-deserialization/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-rsc-dos-flight-deserialization/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-23870. Status: Weaponized. Affects: Next.js App Router (React server-action / RSC reply parser). Tags: DoS, RSC, React-Flight, deserialization, cyclic-payload, Next.js, App-Router, unauthenticated, pre-auth.</description><category>web</category><category>High</category><category>DoS</category><category>RSC</category><category>React-Flight</category><category>deserialization</category><category>cyclic-payload</category><category>Next.js</category><category>App-Router</category><category>unauthenticated</category><category>pre-auth</category></item><item><title>Next.js Image Optimization API OOM DoS (Self-Hosted) (CVE-2026-44577)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-image-optimization-api-oom-dos-self-hosted/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-image-optimization-api-oom-dos-self-hosted/</guid><description>Medium severity (CVSS 5.9) — web · CVE-2026-44577. Status: Weaponized. Affects: Next.js Image Optimization API (/_next/image) on self-hosted deployments. Tags: DoS, OOM, image-optimizer, Next.js, self-hosted, unauthenticated.</description><category>web</category><category>Medium</category><category>DoS</category><category>OOM</category><category>image-optimizer</category><category>Next.js</category><category>self-hosted</category><category>unauthenticated</category></item><item><title>Next.js Cache Components Connection Exhaustion DoS (CVE-2026-44579)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-cache-components-connection-exhaustion-dos/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_nextjs-cache-components-connection-exhaustion-dos/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-44579. Status: Weaponized. Affects: Next.js applications using Cache Components / Partial Prerendering (PPR). Tags: DoS, connection-exhaustion, next-resume, Next.js, cache-components, unauthenticated.</description><category>web</category><category>High</category><category>DoS</category><category>connection-exhaustion</category><category>next-resume</category><category>Next.js</category><category>cache-components</category><category>unauthenticated</category></item><item><title>LDAP Nightmare — Windows LDAP Client RCE/DoS (CVE-2024-49113)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-15_ldap-nightmare-cve-2024-49113/</link><pubDate>Fri, 15 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-15_ldap-nightmare-cve-2024-49113/</guid><description>Critical severity — network · CVE-2024-49113. Status: Weaponized. Affects: Microsoft Windows LDAP client / Netlogon interaction path. Tags: LDAP, NRPC, Windows Server, unauthenticated, DoS, potential-RCE.</description><category>network</category><category>Critical</category><category>LDAP</category><category>NRPC</category><category>Windows Server</category><category>unauthenticated</category><category>DoS</category><category>potential-RCE</category></item></channel></rss>