PoC Archive PoC Archive

tag

Heap-Overflow

nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)
CVE-2026-42533 web Patched
CVE-2026-42533webCRITICAL 9.8Patched2026-08-16Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452) KEV
CVE-2026-8452 network Patched
CVE-2026-8452networkCRITICAL 9.8Patched2026-08-16Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)
CVE-2026-54992 network Patched
CVE-2026-54992networkHIGH 8.4Patched2026-07-27XNU PF_ROUTE RTA_GENMASK Heap Buffer Overflow (CVE-2026-20698)
CVE-2026-20698 binary Patched
CVE-2026-20698binaryHIGHPatched2026-07-05Wyze Cam Pan v3 / TUTK SDK — tutk_packet_alloc Heap Overflow (CVE-2026-38698)
CVE-2026-38698 network Unverified
CVE-2026-38698networkCRITICALUnverified2026-07-05rldns 1.3 Heap-Based Out-of-Bounds Read Remote DoS (CVE-2026-27831)
CVE-2026-27831 binary Patched
CVE-2026-27831binaryMEDIUMPatched2026-07-05PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005
CVE-2026-2005 binary Unverified
CVE-2026-2005binaryCRITICALUnverified2026-07-05Ollama GGUF Heap Out-of-Bounds Read During Quantization — CVE-2026-7482
CVE-2026-7482 misc Patched
CVE-2026-7482miscMEDIUMPatched2026-07-05Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)
CVE-2026-0211 (repository explicitly labels this as a hypothetical/simulated CVE for coursework, not a confirmed vendor-assigned vulnerability) web Unverified
CVE-2026-0211webHIGHUnverified2026-07-05nginx PoolSlip × Rift Chained ASLR-Independent Remote Code Execution (CVE-2026-9256 / CVE-2026-42945)
CVE-2026-9256 ("PoolSlip"), chained with CVE-2026-42945 ("rift") web Unverified
CVE-2026-9256webCRITICALUnverified2026-07-05MariaDB JSON_SCHEMA_VALID() Heap Overflow — Privilege Escalation to UDF RCE (CVE-2026-32710)
CVE-2026-32710 binary Patched
CVE-2026-32710binaryCRITICALPatched2026-07-05libopenapv / Android APV Codec Zero-Click Heap Buffer Overflow (CVE-2026-0006)
CVE-2026-0006 binary Unverified
CVE-2026-0006binaryCRITICAL 9.8Unverified2026-07-05gdk-pixbuf JPEG Loader Heap Buffer Overflow — CVE-2026-5201
CVE-2026-5201 binary Patched
CVE-2026-5201binaryHIGH 7.5Patched2026-07-05VLC Bundled FFmpeg VP9 Decoder Resolution-Change Heap Crash
None assigned as of 2026-07-03 binary Unverified
None assigned as of 2026-07-03binaryMEDIUMUnverified2026-07-03Pillow ImageCms Mutable output_mode Heap OOB Write
None assigned as of 2026-07-03 binary Unverified
None assigned as of 2026-07-03binaryHIGHUnverified2026-07-03libssh2 Unchecked SSH packet_length Integer Wrap to RCE (CVE-2026-55200)
CVE-2026-55200 network Patched
CVE-2026-55200networkCRITICALPatched2026-07-03libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution
None assigned as of 2026-07-03 network Unverified
None assigned as of 2026-07-03networkCRITICALUnverified2026-07-03FFmpeg RASC Decoder DLTA Heap Out-of-Bounds Write
None assigned as of 2026-07-03 binary Unpatched
None assigned as of 2026-07-03binaryCRITICALUnpatched2026-07-03Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)
CVE-2026-47729 network Patched
CVE-2026-47729networkMEDIUMPatched2026-07-01VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079) KEV EPSS 22%
CVE-2024-37079 network Patched
CVE-2024-37079networkCRITICAL 9.8Patched2026-05-16NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945) EPSS 68%
CVE-2026-42945 web Unverified
CVE-2026-42945webCRITICAL 9.8Unverified2026-05-14