<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Heap-Corruption — PoC Archive</title><link>https://poc.intelseclab.com/tags/heap-corruption/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/heap-corruption/index.xml" rel="self" type="application/rss+xml"/><item><title>Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-54957-dolby-decoder-oob-write/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-54957-dolby-decoder-oob-write/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2025-54957. Status: Weaponized. Affects: Dolby Digital Plus (DDPlus) Unified Decoder — bundled in Android media stack, iOS/macOS CoreAudio-adjacent decoders, and ChromeOS. Tags: dolby, ddplus, ac-3, ec-3, audio-codec, out-of-bounds-write, integer-overflow, zero-click, android, ios, macos, heap-corruption.</description><category>binary</category><category>Critical</category><category>dolby</category><category>ddplus</category><category>ac-3</category><category>ec-3</category><category>audio-codec</category><category>out-of-bounds-write</category><category>integer-overflow</category><category>zero-click</category><category>android</category><category>ios</category><category>macos</category><category>heap-corruption</category></item><item><title>Tasmota fetch_jpg() Integer Wraparound to Heap Corruption (CVE-2026-38427)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38427-tasmota-fetchjpg-integer-wraparound/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38427-tasmota-fetchjpg-integer-wraparound/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-38427. Status: PoC. Affects: Arendst Tasmota (ESP32 firmware). Tags: tasmota, esp32, iot, integer-overflow, heap-corruption, rce, mjpeg, scripter.</description><category>network</category><category>Critical</category><category>tasmota</category><category>esp32</category><category>iot</category><category>integer-overflow</category><category>heap-corruption</category><category>rce</category><category>mjpeg</category><category>scripter</category></item><item><title>OP-TEE PKCS#11 TA Out-of-Bounds Heap Write via `C_GetAttributeValue` (CVE-2026-33317)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-33317-optee-pkcs11-heap-oob-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-33317-optee-pkcs11-heap-oob-write/</guid><description>High severity (CVSS 8.7) — binary · CVE-2026-33317 (GHSA-8cqw-mg7v-c9p9). Status: PoC. Affects: OP-TEE OS — PKCS#11 Trusted Application (optee_os, ta/pkcs11). Tags: optee, trustzone, pkcs11, secure-world, heap-corruption, oob-write, qemu, trusted-application.</description><category>binary</category><category>High</category><category>optee</category><category>trustzone</category><category>pkcs11</category><category>secure-world</category><category>heap-corruption</category><category>oob-write</category><category>qemu</category><category>trusted-application</category></item><item><title>Redis Vector Set Duplicate HNSW Node ID RCE</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_redis-vector-set-hnsw-id-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_redis-vector-set-hnsw-id-rce/</guid><description>Critical severity — network · None assigned as of 2026-07-03. Status: Weaponized. Affects: Redis server, Vector Set module (modules/vector-sets). Tags: redis, vector-set, hnsw, rce, deserialization, use-after-free, heap-corruption, rdb-restore.</description><category>network</category><category>Critical</category><category>redis</category><category>vector-set</category><category>hnsw</category><category>rce</category><category>deserialization</category><category>use-after-free</category><category>heap-corruption</category><category>rdb-restore</category></item><item><title>c-ares TCP ares_getaddrinfo() Use-After-Free Code Execution</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_c-ares-tcp-getaddrinfo-uaf/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_c-ares-tcp-getaddrinfo-uaf/</guid><description>High severity — network · None assigned as of 2026-07-03. Status: PoC. Affects: c-ares (async DNS resolver library). Tags: c-ares, use-after-free, dns, resolver, tcp, heap-corruption, code-execution, edns.</description><category>network</category><category>High</category><category>c-ares</category><category>use-after-free</category><category>dns</category><category>resolver</category><category>tcp</category><category>heap-corruption</category><category>code-execution</category><category>edns</category></item><item><title>libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-55200-libssh2-oob-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-55200-libssh2-oob-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-55200. Status: PoC. Affects: libssh2 (SSH client library). Tags: RCE, OOB-write, heap-corruption, libssh2, SSH, integer-overflow, unauthenticated, C, network.</description><category>network</category><category>Critical</category><category>RCE</category><category>OOB-write</category><category>heap-corruption</category><category>libssh2</category><category>SSH</category><category>integer-overflow</category><category>unauthenticated</category><category>C</category><category>network</category></item><item><title>FFmpeg MagicYUV Decoder Out-of-Bounds Write / RCE — PixelSmash (CVE-2026-8461)</title><link>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-8461-ffmpeg-magicyuv-oob-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-06-30_cve-2026-8461-ffmpeg-magicyuv-oob-rce/</guid><description>High severity (CVSS 8.8) — binary · CVE-2026-8461. Status: PoC. Affects: FFmpeg libavcodec — MagicYUV video decoder. Tags: RCE, OOB-write, heap-corruption, FFmpeg, MagicYUV, media, video, PixelSmash, libavcodec, Python, High.</description><category>binary</category><category>High</category><category>RCE</category><category>OOB-write</category><category>heap-corruption</category><category>FFmpeg</category><category>MagicYUV</category><category>media</category><category>video</category><category>PixelSmash</category><category>libavcodec</category><category>Python</category><category>High</category></item><item><title>Windows Kernel Elevation of Privilege - Race Condition / Double-Free (CVE-2025-62215)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-kernel-eop-cve-2025-62215/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-17_windows-kernel-eop-cve-2025-62215/</guid><description>High severity (CVSS 7) — binary · CVE-2025-62215. Status: Weaponized. Affects: Windows Kernel (ntoskrnl.exe / kernel resource synchronization). Tags: EoP, Windows kernel, race condition, double-free, heap corruption, 0day, SYSTEM, Windows 10, Windows 11.</description><category>binary</category><category>High</category><category>EoP</category><category>Windows kernel</category><category>race condition</category><category>double-free</category><category>heap corruption</category><category>0day</category><category>SYSTEM</category><category>Windows 10</category><category>Windows 11</category></item><item><title>Apache httpd mod_http2 Double-Free Pre-Auth RCE - CVE-2026-23918</title><link>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-17_apache-httpd-mod-http2-double-free/</guid><description>Critical severity — web · CVE-2026-23918. Status: Weaponized. Affects: Apache HTTP Server (httpd) with mod_http2. Tags: RCE, pre-auth, unauthenticated, double-free, heap-corruption, Apache, httpd, mod_http2, HTTP/2, TLS.</description><category>web</category><category>Critical</category><category>RCE</category><category>pre-auth</category><category>unauthenticated</category><category>double-free</category><category>heap-corruption</category><category>Apache</category><category>httpd</category><category>mod_http2</category><category>HTTP/2</category><category>TLS</category></item></channel></rss>