<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Heap-Overflow — PoC Archive</title><link>https://poc.intelseclab.com/tags/heap-overflow/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/heap-overflow/index.xml" rel="self" type="application/rss+xml"/><item><title>nginx PCRE Capture Variable Heap Overflow to Pre-Auth RCE (CVE-2026-42533)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-42533-nginx-pcre-heap-overflow-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-42533-nginx-pcre-heap-overflow-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-42533. Status: Patched. Affects: nginx 1.30.1 (and likely earlier versions). Tags: nginx, pcre, heap-overflow, rce, preauth, info-leak, capture-variable, map-directive, aslr-bypass, CVE-2026-42533.</description><category>web</category><category>Critical</category><category>nginx</category><category>pcre</category><category>heap-overflow</category><category>rce</category><category>preauth</category><category>info-leak</category><category>capture-variable</category><category>map-directive</category><category>aslr-bypass</category><category>CVE-2026-42533</category></item><item><title>Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-8452-citrix-netscaler-saml-preauth-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-8452-citrix-netscaler-saml-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-8452. Status: Patched. Affects: Citrix NetScaler ADC and NetScaler Gateway. Tags: citrix, netscaler, adc, gateway, saml, heap-overflow, preauth, rce, shellcode, webshell, freebsd, xml-signature, c14n, CVE-2026-8452.</description><category>network</category><category>Critical</category><category>citrix</category><category>netscaler</category><category>adc</category><category>gateway</category><category>saml</category><category>heap-overflow</category><category>preauth</category><category>rce</category><category>shellcode</category><category>webshell</category><category>freebsd</category><category>xml-signature</category><category>c14n</category><category>CVE-2026-8452</category></item><item><title>Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</guid><description>High severity (CVSS 8.4) — network · CVE-2026-54992. Status: PoC (crash/DoS confirmed, no RCE demonstrated). Affects: Windows Message Queuing (MSMQ) — Queue Manager (mqqm.dll, hosted in mqsvc.exe), reached via the MS-MQRR (RemoteRead) RPC interface. Tags: windows, msmq, message-queuing, heap-overflow, integer-overflow, rpc, dos, crash.</description><category>network</category><category>High</category><category>windows</category><category>msmq</category><category>message-queuing</category><category>heap-overflow</category><category>integer-overflow</category><category>rpc</category><category>dos</category><category>crash</category></item><item><title>XNU PF_ROUTE RTA_GENMASK Heap Buffer Overflow (CVE-2026-20698)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20698-xnu-pf-route-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-20698-xnu-pf-route-heap-overflow/</guid><description>High severity — binary · CVE-2026-20698. Status: PoC. Affects: XNU kernel routing socket subsystem (PF_ROUTE, bsd/net/rtsock.c / bsd/net/radix.c). Tags: xnu, kernel, ios, macos, pf_route, routing-socket, heap-overflow, radix-tree, kernel-panic, bounds-safety.</description><category>binary</category><category>High</category><category>xnu</category><category>kernel</category><category>ios</category><category>macos</category><category>pf_route</category><category>routing-socket</category><category>heap-overflow</category><category>radix-tree</category><category>kernel-panic</category><category>bounds-safety</category></item><item><title>Wyze Cam Pan v3 / TUTK SDK — tutk_packet_alloc Heap Overflow (CVE-2026-38698)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38698-wyze-cam-tutk-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38698-wyze-cam-tutk-heap-overflow/</guid><description>Critical severity — network · CVE-2026-38698. Status: PoC. Affects: TUTK SDK (as used in Wyze Cam Pan v3 and other TUTK-based IoT cameras). Tags: tutk-sdk, iot, camera, heap-overflow, av-server, wyze, authenticated, p2p.</description><category>network</category><category>Critical</category><category>tutk-sdk</category><category>iot</category><category>camera</category><category>heap-overflow</category><category>av-server</category><category>wyze</category><category>authenticated</category><category>p2p</category></item><item><title>rldns 1.3 Heap-Based Out-of-Bounds Read Remote DoS (CVE-2026-27831)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-27831-rldns-heap-oob-read-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-27831-rldns-heap-oob-read-dos/</guid><description>Medium severity — binary · CVE-2026-27831. Status: PoC. Affects: rldns 1.3 (open-source DNS server). Tags: dns, heap-overflow, out-of-bounds-read, denial-of-service, rldns, memory-corruption, x86_64.</description><category>binary</category><category>Medium</category><category>dns</category><category>heap-overflow</category><category>out-of-bounds-read</category><category>denial-of-service</category><category>rldns</category><category>memory-corruption</category><category>x86_64</category></item><item><title>PostgreSQL pgcrypto PGP Heap Overflow to Superuser Escalation — CVE-2026-2005</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2005-postgresql-pgcrypto-heapoverflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-2005-postgresql-pgcrypto-heapoverflow/</guid><description>Critical severity — binary · CVE-2026-2005. Status: PoC. Affects: PostgreSQL pgcrypto extension (PGP session-key parsing). Tags: postgresql, pgcrypto, heap-overflow, aslr-bypass, privilege-escalation, pgp, memory-corruption.</description><category>binary</category><category>Critical</category><category>postgresql</category><category>pgcrypto</category><category>heap-overflow</category><category>aslr-bypass</category><category>privilege-escalation</category><category>pgp</category><category>memory-corruption</category></item><item><title>Ollama GGUF Heap Out-of-Bounds Read During Quantization — CVE-2026-7482</title><link>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-7482-poc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/misc/2026-07-05_cve-2026-7482-poc/</guid><description>Medium severity — misc · CVE-2026-7482. Status: PoC. Affects: Ollama (GGUF model loader / quantization pipeline). Tags: ollama, gguf, heap-overflow, out-of-bounds-read, quantization, llm-serving, docker.</description><category>misc</category><category>Medium</category><category>ollama</category><category>gguf</category><category>heap-overflow</category><category>out-of-bounds-read</category><category>quantization</category><category>llm-serving</category><category>docker</category></item><item><title>Nginx QUIC/HTTP-3 DCID Length Heap Overflow Lab (CVE-2026-0211)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0211-nginx-quic-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0211-nginx-quic-heap-overflow/</guid><description>High severity — web · CVE-2026-0211 (repository explicitly labels this as a hypothetical/simulated CVE for coursework, not a confirmed vendor-assigned vulnerability). Status: PoC. Affects: A custom, deliberately vulnerabilized fork of Nginx 1.25.3's QUIC transport module (ngx_event_quic_transport.c), run inside a purpose-built Docker lab — not the stock upstream Nginx release. Tags: nginx, quic, http-3, heap-overflow, dos, fuzzing, dcid, academic-lab, docker.</description><category>web</category><category>High</category><category>nginx</category><category>quic</category><category>http-3</category><category>heap-overflow</category><category>dos</category><category>fuzzing</category><category>dcid</category><category>academic-lab</category><category>docker</category></item><item><title>nginx PoolSlip × Rift Chained ASLR-Independent Remote Code Execution (CVE-2026-9256 / CVE-2026-42945)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-9256-nginx-poolslip-rift-rce-chain/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-9256-nginx-poolslip-rift-rce-chain/</guid><description>Critical severity — web · CVE-2026-9256 ("PoolSlip"), chained with CVE-2026-42945 ("rift"). Status: PoC. Affects: nginx (rewrite engine). Tags: nginx, heap-overflow, heap-over-read, aslr-bypass, rce, rewrite-engine, request-smuggling-adjacent, chained-exploit.</description><category>web</category><category>Critical</category><category>nginx</category><category>heap-overflow</category><category>heap-over-read</category><category>aslr-bypass</category><category>rce</category><category>rewrite-engine</category><category>request-smuggling-adjacent</category><category>chained-exploit</category></item><item><title>MariaDB JSON_SCHEMA_VALID() Heap Overflow — Privilege Escalation to UDF RCE (CVE-2026-32710)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-32710-mariadb-json-schema-udf-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-32710-mariadb-json-schema-udf-rce/</guid><description>Critical severity — binary · CVE-2026-32710. Status: PoC. Affects: MariaDB (JSON_SCHEMA_VALID() SQL function). Tags: mariadb, mysql, heap-overflow, privilege-escalation, udf, raptor-udf, sql, json, docker-lab.</description><category>binary</category><category>Critical</category><category>mariadb</category><category>mysql</category><category>heap-overflow</category><category>privilege-escalation</category><category>udf</category><category>raptor-udf</category><category>sql</category><category>json</category><category>docker-lab</category></item><item><title>libopenapv / Android APV Codec Zero-Click Heap Buffer Overflow (CVE-2026-0006)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0006-openapv-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-0006-openapv-heap-overflow/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2026-0006. Status: PoC. Affects: libopenapv (Samsung APV — Advanced Professional Video — codec), integrated into Android 16 as a Mainline module (mediaswcodec / C2SoftApvDec). Tags: android, libopenapv, apv-codec, heap-overflow, zero-click, media-framework, mediaswcodec, mainline-module.</description><category>binary</category><category>Critical</category><category>android</category><category>libopenapv</category><category>apv-codec</category><category>heap-overflow</category><category>zero-click</category><category>media-framework</category><category>mediaswcodec</category><category>mainline-module</category></item><item><title>gdk-pixbuf JPEG Loader Heap Buffer Overflow — CVE-2026-5201</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-5201-gdk-pixbuf-jpeg-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-5201-gdk-pixbuf-jpeg-heap-overflow/</guid><description>High severity (CVSS 7.5) — binary · CVE-2026-5201. Status: PoC. Affects: gdk-pixbuf (GNOME image loading library), JPEG loader (io-jpeg.c). Tags: gdk-pixbuf, jpeg, libjpeg, heap-overflow, gnome, gtk, linux-desktop, cwe-122, vtable-hijack.</description><category>binary</category><category>High</category><category>gdk-pixbuf</category><category>jpeg</category><category>libjpeg</category><category>heap-overflow</category><category>gnome</category><category>gtk</category><category>linux-desktop</category><category>cwe-122</category><category>vtable-hijack</category></item><item><title>VLC Bundled FFmpeg VP9 Decoder Resolution-Change Heap Crash</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_vlc-vp9-reschange-crash/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_vlc-vp9-reschange-crash/</guid><description>Medium severity — binary · None assigned as of 2026-07-03. Status: Incomplete PoC. Affects: VLC media player, bundled FFmpeg VP9 decoder (plugins/codec/libavcodec_plugin.dll). Tags: vlc, ffmpeg, vp9, ivf, heap-overflow, media-parsing, crash, windows, decoder.</description><category>binary</category><category>Medium</category><category>vlc</category><category>ffmpeg</category><category>vp9</category><category>ivf</category><category>heap-overflow</category><category>media-parsing</category><category>crash</category><category>windows</category><category>decoder</category></item><item><title>Pillow ImageCms Mutable output_mode Heap OOB Write</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_pillow-imagecms-output-mode-oob-write/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_pillow-imagecms-output-mode-oob-write/</guid><description>High severity — binary · None assigned as of 2026-07-03. Status: PoC. Affects: Pillow (Python Imaging Library fork), PIL.ImageCms module. Tags: pillow, imagecms, littlecms, heap-overflow, oob-write, python, image-processing, memory-corruption.</description><category>binary</category><category>High</category><category>pillow</category><category>imagecms</category><category>littlecms</category><category>heap-overflow</category><category>oob-write</category><category>python</category><category>image-processing</category><category>memory-corruption</category></item><item><title>libssh2 Unchecked SSH packet_length Integer Wrap to RCE (CVE-2026-55200)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-55200-libssh2-packet-length-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-55200-libssh2-packet-length-rce/</guid><description>Critical severity — network · CVE-2026-55200. Status: Weaponized. Affects: libssh2, ssh2_transport_read() in src/transport.c. Tags: libssh2, ssh, integer-overflow, heap-overflow, packet-length, transport, rce, memory-corruption, cve-2026-55200.</description><category>network</category><category>Critical</category><category>libssh2</category><category>ssh</category><category>integer-overflow</category><category>heap-overflow</category><category>packet-length</category><category>transport</category><category>rce</category><category>memory-corruption</category><category>cve-2026-55200</category></item><item><title>libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_libssh2-publickey-list-parser-oob/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_libssh2-publickey-list-parser-oob/</guid><description>Critical severity — network · None assigned as of 2026-07-03. Status: Weaponized. Affects: libssh2, publickey subsystem list parser (src/publickey.c). Tags: libssh2, ssh, publickey-subsystem, heap-overflow, use-after-free, integer-overflow, windows, rce, memory-corruption.</description><category>network</category><category>Critical</category><category>libssh2</category><category>ssh</category><category>publickey-subsystem</category><category>heap-overflow</category><category>use-after-free</category><category>integer-overflow</category><category>windows</category><category>rce</category><category>memory-corruption</category></item><item><title>FFmpeg RASC Decoder DLTA Heap Out-of-Bounds Write</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_ffmpeg-rasc-dlta-heap-oob-write/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_ffmpeg-rasc-dlta-heap-oob-write/</guid><description>Critical severity — binary · None assigned as of 2026-07-03. Status: PoC. Affects: FFmpeg, libavcodec RASC decoder (AV_CODEC_ID_RASC). Tags: ffmpeg, libavcodec, heap-overflow, rasc, oob-write, media-parsing, codec, memory-corruption.</description><category>binary</category><category>Critical</category><category>ffmpeg</category><category>libavcodec</category><category>heap-overflow</category><category>rasc</category><category>oob-write</category><category>media-parsing</category><category>codec</category><category>memory-corruption</category></item><item><title>Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-47729-squidbleed-squid-ftp-oob-read/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-47729-squidbleed-squid-ftp-oob-read/</guid><description>Medium severity — network · CVE-2026-47729. Status: PoC. Affects: Squid Proxy — FTP gateway / directory-listing parser. Tags: memory-disclosure, information-disclosure, Squid, proxy, FTP, heap-overflow, oob-read, credential-theft, legacy.</description><category>network</category><category>Medium</category><category>memory-disclosure</category><category>information-disclosure</category><category>Squid</category><category>proxy</category><category>FTP</category><category>heap-overflow</category><category>oob-read</category><category>credential-theft</category><category>legacy</category></item><item><title>VMware vCenter Server DCE/RPC Heap Overflow RCE (CVE-2024-37079)</title><link>https://poc.intelseclab.com/pocs/network/2026-05-16_vmware-vcenter-dcerpc-heap-overflow-rce/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-16_vmware-vcenter-dcerpc-heap-overflow-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2024-37079. Status: Weaponized. Affects: VMware vCenter Server. Tags: RCE, heap-overflow, DCE/RPC, vCenter, unauthenticated, KEV.</description><category>network</category><category>Critical</category><category>RCE</category><category>heap-overflow</category><category>DCE/RPC</category><category>vCenter</category><category>unauthenticated</category><category>KEV</category></item><item><title>NGINX Rift — Heap Buffer Overflow RCE (CVE-2026-42945)</title><link>https://poc.intelseclab.com/pocs/web/2026-05-14_nginx-rift-cve-2026-42945/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-05-14_nginx-rift-cve-2026-42945/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-42945. Status: Weaponized. Affects: NGINX Open Source / NGINX Plus. Tags: RCE, unauthenticated, nginx, heap-overflow, buffer-overflow, rewrite.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>nginx</category><category>heap-overflow</category><category>buffer-overflow</category><category>rewrite</category></item></channel></rss>