PoC Archive PoC Archive

tag

Heap-Corruption

Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)
CVE-2025-54957 binary Unverified
CVE-2025-54957binaryCRITICAL 9.8Unverified2026-07-06Tasmota fetch_jpg() Integer Wraparound to Heap Corruption (CVE-2026-38427)
CVE-2026-38427 network Patched
CVE-2026-38427networkCRITICAL 9.8Patched2026-07-05OP-TEE PKCS#11 TA Out-of-Bounds Heap Write via `C_GetAttributeValue` (CVE-2026-33317)
CVE-2026-33317 (GHSA-8cqw-mg7v-c9p9) binary Patched
CVE-2026-33317binaryHIGH 8.7Patched2026-07-05Redis Vector Set Duplicate HNSW Node ID RCE
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkCRITICALUnverified2026-07-03c-ares TCP ares_getaddrinfo() Use-After-Free Code Execution
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkHIGHUnverified2026-07-03libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)
CVE-2026-55200 network Patched
CVE-2026-55200networkCRITICAL 9.8Patched2026-06-30FFmpeg MagicYUV Decoder Out-of-Bounds Write / RCE — PixelSmash (CVE-2026-8461)
CVE-2026-8461 binary Patched
CVE-2026-8461binaryHIGH 8.8Patched2026-06-30Windows Kernel Elevation of Privilege - Race Condition / Double-Free (CVE-2025-62215) KEV
CVE-2025-62215 binary Patched
CVE-2025-62215binaryHIGH 7Patched2026-05-17Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918 EPSS 50%
CVE-2026-23918 web Patched
CVE-2026-23918webCRITICALPatched2026-05-17