<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Integer-Overflow — PoC Archive</title><link>https://poc.intelseclab.com/tags/integer-overflow/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/integer-overflow/index.xml" rel="self" type="application/rss+xml"/><item><title>Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</guid><description>High severity (CVSS 8.4) — network · CVE-2026-54992. Status: PoC (crash/DoS confirmed, no RCE demonstrated). Affects: Windows Message Queuing (MSMQ) — Queue Manager (mqqm.dll, hosted in mqsvc.exe), reached via the MS-MQRR (RemoteRead) RPC interface. Tags: windows, msmq, message-queuing, heap-overflow, integer-overflow, rpc, dos, crash.</description><category>network</category><category>High</category><category>windows</category><category>msmq</category><category>message-queuing</category><category>heap-overflow</category><category>integer-overflow</category><category>rpc</category><category>dos</category><category>crash</category></item><item><title>Dolby Unified (DDPlus) Decoder Out-of-Bounds Write via Evolution Data (CVE-2025-54957)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-54957-dolby-decoder-oob-write/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-06_cve-2025-54957-dolby-decoder-oob-write/</guid><description>Critical severity (CVSS 9.8) — binary · CVE-2025-54957. Status: Weaponized. Affects: Dolby Digital Plus (DDPlus) Unified Decoder — bundled in Android media stack, iOS/macOS CoreAudio-adjacent decoders, and ChromeOS. Tags: dolby, ddplus, ac-3, ec-3, audio-codec, out-of-bounds-write, integer-overflow, zero-click, android, ios, macos, heap-corruption.</description><category>binary</category><category>Critical</category><category>dolby</category><category>ddplus</category><category>ac-3</category><category>ec-3</category><category>audio-codec</category><category>out-of-bounds-write</category><category>integer-overflow</category><category>zero-click</category><category>android</category><category>ios</category><category>macos</category><category>heap-corruption</category></item><item><title>Windows HTTP.sys Header-Count-Triggered Kernel Memory Corruption / BSOD (CVE-2026-49160)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-49160-http-sys-http2-bomb-dos/</guid><description>High severity — binary · CVE-2026-49160. Status: PoC. Affects: Windows HTTP.sys kernel-mode driver (Windows 10 build 26100 confirmed in crash logs). Tags: windows, http.sys, kernel, http2, dos, bsod, memory-corruption, integer-overflow.</description><category>binary</category><category>High</category><category>windows</category><category>http.sys</category><category>kernel</category><category>http2</category><category>dos</category><category>bsod</category><category>memory-corruption</category><category>integer-overflow</category></item><item><title>VirtualBox DevVGA_VBVA Integer Overflow leading to Guest-Triggerable DoS (CVE-2026-35250)</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-35250-virtualbox-vbva-integer-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-05_cve-2026-35250-virtualbox-vbva-integer-overflow/</guid><description>Low severity (CVSS 2.3) — binary · CVE-2026-35250. Status: PoC. Affects: Oracle VirtualBox — DevVGA_VBVA.cpp. Tags: virtualbox, integer-overflow, dos, vbva, guest-to-host, cwe-190, ai-assisted-research.</description><category>binary</category><category>Low</category><category>virtualbox</category><category>integer-overflow</category><category>dos</category><category>vbva</category><category>guest-to-host</category><category>cwe-190</category><category>ai-assisted-research</category></item><item><title>Tasmota fetch_jpg() Integer Wraparound to Heap Corruption (CVE-2026-38427)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38427-tasmota-fetchjpg-integer-wraparound/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38427-tasmota-fetchjpg-integer-wraparound/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-38427. Status: PoC. Affects: Arendst Tasmota (ESP32 firmware). Tags: tasmota, esp32, iot, integer-overflow, heap-corruption, rce, mjpeg, scripter.</description><category>network</category><category>Critical</category><category>tasmota</category><category>esp32</category><category>iot</category><category>integer-overflow</category><category>heap-corruption</category><category>rce</category><category>mjpeg</category><category>scripter</category></item><item><title>Tasmota fetch_jpg() Combined Buffer Overflow RCE Chain (CVE-2026-38422)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38422-tasmota-fetchjpg-combined-overflow-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38422-tasmota-fetchjpg-combined-overflow-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-38422. Status: PoC. Affects: Arendst Tasmota (ESP32 firmware). Tags: tasmota, esp32, iot, buffer-overflow, integer-overflow, rce, mjpeg, scripter.</description><category>network</category><category>Critical</category><category>tasmota</category><category>esp32</category><category>iot</category><category>buffer-overflow</category><category>integer-overflow</category><category>rce</category><category>mjpeg</category><category>scripter</category></item><item><title>PgBouncer SASL Length Field Integer Overflow Crash — CVE-2026-6664</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6664-pgbouncer-integer-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-6664-pgbouncer-integer-overflow/</guid><description>High severity — network · CVE-2026-6664. Status: PoC. Affects: PgBouncer (PostgreSQL connection pooler). Tags: pgbouncer, postgresql, integer-overflow, sasl, scram, dos, cwe-190.</description><category>network</category><category>High</category><category>pgbouncer</category><category>postgresql</category><category>integer-overflow</category><category>sasl</category><category>scram</category><category>dos</category><category>cwe-190</category></item><item><title>libssh2 Unchecked SSH packet_length Integer Wrap to RCE (CVE-2026-55200)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-55200-libssh2-packet-length-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-55200-libssh2-packet-length-rce/</guid><description>Critical severity — network · CVE-2026-55200. Status: Weaponized. Affects: libssh2, ssh2_transport_read() in src/transport.c. Tags: libssh2, ssh, integer-overflow, heap-overflow, packet-length, transport, rce, memory-corruption, cve-2026-55200.</description><category>network</category><category>Critical</category><category>libssh2</category><category>ssh</category><category>integer-overflow</category><category>heap-overflow</category><category>packet-length</category><category>transport</category><category>rce</category><category>memory-corruption</category><category>cve-2026-55200</category></item><item><title>libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_libssh2-publickey-list-parser-oob/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_libssh2-publickey-list-parser-oob/</guid><description>Critical severity — network · None assigned as of 2026-07-03. Status: Weaponized. Affects: libssh2, publickey subsystem list parser (src/publickey.c). Tags: libssh2, ssh, publickey-subsystem, heap-overflow, use-after-free, integer-overflow, windows, rce, memory-corruption.</description><category>network</category><category>Critical</category><category>libssh2</category><category>ssh</category><category>publickey-subsystem</category><category>heap-overflow</category><category>use-after-free</category><category>integer-overflow</category><category>windows</category><category>rce</category><category>memory-corruption</category></item><item><title>libarchive ZIP Declared-Size Boundary Bypass via debuginfod</title><link>https://poc.intelseclab.com/pocs/binary/2026-07-03_libarchive-zip-debuginfod-size-boundary/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-07-03_libarchive-zip-debuginfod-size-boundary/</guid><description>Medium severity — binary · None assigned as of 2026-07-03. Status: PoC. Affects: libarchive (ZIP reader) and elfutils debuginfod. Tags: libarchive, zip, zip64, integer-overflow, debuginfod, elfutils, size-validation, boundary-bypass.</description><category>binary</category><category>Medium</category><category>libarchive</category><category>zip</category><category>zip64</category><category>integer-overflow</category><category>debuginfod</category><category>elfutils</category><category>size-validation</category><category>boundary-bypass</category></item><item><title>libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-55200-libssh2-oob-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-55200-libssh2-oob-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-55200. Status: PoC. Affects: libssh2 (SSH client library). Tags: RCE, OOB-write, heap-corruption, libssh2, SSH, integer-overflow, unauthenticated, C, network.</description><category>network</category><category>Critical</category><category>RCE</category><category>OOB-write</category><category>heap-corruption</category><category>libssh2</category><category>SSH</category><category>integer-overflow</category><category>unauthenticated</category><category>C</category><category>network</category></item></channel></rss>