<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Oob-Read — PoC Archive</title><link>https://poc.intelseclab.com/tags/oob-read/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/oob-read/index.xml" rel="self" type="application/rss+xml"/><item><title>MariaDB — Low-Privilege Remote Code Execution via ST_Area OOB Read + SYS_REFCURSOR Use-After-Free</title><link>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-08-09_mariadb-low-priv-rce-st-area-cursor-uaf/</guid><description>Critical severity (CVSS 8.8) — binary · MDEV-40328 (ST_Area OOB read); cursor-array UAF has no assigned CVE yet. Status: Unpatched. Affects: MariaDB Server, ST_Area() geometry function and SYS_REFCURSOR cursor-array management. Tags: mariadb, database, rce, low-privilege, heap, oob-read, use-after-free, aslr-bypass, pie-bypass, coop, vtable, cursor, st-area, multipolygon, CWE-125, CWE-416, docker, v12-security.</description><category>binary</category><category>Critical</category><category>mariadb</category><category>database</category><category>rce</category><category>low-privilege</category><category>heap</category><category>oob-read</category><category>use-after-free</category><category>aslr-bypass</category><category>pie-bypass</category><category>coop</category><category>vtable</category><category>cursor</category><category>st-area</category><category>multipolygon</category><category>CWE-125</category><category>CWE-416</category><category>docker</category><category>v12-security</category></item><item><title>Squidbleed — Squid Proxy FTP Gateway Out-of-Bounds Heap Read (CVE-2026-47729)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-47729-squidbleed-squid-ftp-oob-read/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-01_cve-2026-47729-squidbleed-squid-ftp-oob-read/</guid><description>Medium severity — network · CVE-2026-47729. Status: PoC. Affects: Squid Proxy — FTP gateway / directory-listing parser. Tags: memory-disclosure, information-disclosure, Squid, proxy, FTP, heap-overflow, oob-read, credential-theft, legacy.</description><category>network</category><category>Medium</category><category>memory-disclosure</category><category>information-disclosure</category><category>Squid</category><category>proxy</category><category>FTP</category><category>heap-overflow</category><category>oob-read</category><category>credential-theft</category><category>legacy</category></item><item><title>Notepad++ &lt;= 8.9.6 Multiple Vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800)</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-28_notepad-plus-plus-8-9-6-multi-cve/</link><pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-28_notepad-plus-plus-8-9-6-multi-cve/</guid><description>High severity (CVSS 5) — binary · CVE-2026-48770, CVE-2026-48778, CVE-2026-48800. Status: Patched. Affects: Notepad++. Tags: Notepad++, Windows, OOB-read, DoS, command-injection, config.xml, shortcuts.xml, local.</description><category>binary</category><category>High</category><category>Notepad++</category><category>Windows</category><category>OOB-read</category><category>DoS</category><category>command-injection</category><category>config.xml</category><category>shortcuts.xml</category><category>local</category></item><item><title>QEMUtiny - QEMU CXL Type-3 Memory Corruption Chain</title><link>https://poc.intelseclab.com/pocs/binary/2026-05-16_qemutiny-memory-corruption/</link><pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/binary/2026-05-16_qemutiny-memory-corruption/</guid><description>Critical severity — binary. Status: Weaponized. Affects: QEMU CXL Type-3 device emulation (hw/cxl/cxl-mailbox-utils.c). Tags: QEMU, CXL, memory-corruption, OOB-read, OOB-write, guest-to-host-escape, local, root-in-guest.</description><category>binary</category><category>Critical</category><category>QEMU</category><category>CXL</category><category>memory-corruption</category><category>OOB-read</category><category>OOB-write</category><category>guest-to-host-escape</category><category>local</category><category>root-in-guest</category></item></channel></rss>