An open API service indexing awesome lists of open source software.

https://github.com/qazbnm456/awesome-cve-poc

✍️ A curated list of CVE PoCs.
https://github.com/qazbnm456/awesome-cve-poc

awesome cve poc

Last synced: about 1 year ago
JSON representation

✍️ A curated list of CVE PoCs.

Awesome Lists containing this project

README

          

# Awesome CVE PoC [![Awesome](https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg)](https://github.com/sindresorhus/awesome)

[](https://cve.mitre.org/index.html)

> ✍️ A curated list of CVE PoCs.

Here is a collection about Proof of Concepts of Common Vulnerabilities and Exposures, and you may also want to check out [awesome-web-security](https://github.com/qazbnm456/awesome-web-security).

*Please read the [contribution guidelines](CONTRIBUTING.md) before contributing.*

---

🌈 This repo is full of PoCs for CVEs.

---

If you enjoy this awesome list and would like to support it, check out my [Patreon](https://www.patreon.com/boik) page :)
Also, don't forget to check out my [repos](https://github.com/qazbnm456) 🐾 or say *hi* on my [Twitter](https://twitter.com/qazbnm456)!

## Contents

- [CVE-2011-2856](#cve-2011-2856)
- [CVE-2011-3243](#cve-2011-3243)
- [CVE-2013-2618](#cve-2013-2618)
- [CVE-2013-6632](#cve-2013-6632)
- [CVE-2014-1701](#cve-2014-1701)
- [CVE-2014-1705](#cve-2014-1705)
- [CVE-2014-1747](#cve-2014-1747)
- [CVE-2014-3176](#cve-2014-3176)
- [CVE-2014-6332](#cve-2014-6332)
- [CVE-2014-7927](#cve-2014-7927)
- [CVE-2014-7928](#cve-2014-7928)
- [CVE-2015-0072](#cve-2015-0072)
- [CVE-2015-0235](#cve-2015-0235)
- [CVE-2015-0240](#cve-2015-0240)
- [CVE-2015-1233](#cve-2015-1233)
- [CVE-2015-1242](#cve-2015-1242)
- [CVE-2015-1268](#cve-2015-1268)
- [CVE-2015-1635](#cve-2015-1635)
- [CVE-2015-1830](#cve-2015-1830)
- [CVE-2015-2177](#cve-2015-2177)
- [CVE-2015-3306](#cve-2015-3306)
- [CVE-2015-5119](#cve-2015-5119)
- [CVE-2015-5254](#cve-2015-5254)
- [CVE-2015-5531](#cve-2015-5531)
- [CVE-2015-6086](#cve-2015-6086)
- [CVE-2015-6755](#cve-2015-6755)
- [CVE-2015-6764](#cve-2015-6764)
- [CVE-2015-6769](#cve-2015-6769)
- [CVE-2015-6770](#cve-2015-6770)
- [CVE-2015-6771](#cve-2015-6771)
- [CVE-2015-7450](#cve-2015-7450)
- [CVE-2015-7501](#cve-2015-7501)
- [CVE-2015-7545](#cve-2015-7545)
- [CVE-2015-8584](#cve-2015-8584)
- [CVE-2016-0040](#cve-2016-0040)
- [CVE-2016-0450](#cve-2016-0450)
- [CVE-2016-0451](#cve-2016-0451)
- [CVE-2016-0728](#cve-2016-0728)
- [CVE-2016-0792](#cve-2016-0792)
- [CVE-2016-0856](#cve-2016-0856)
- [CVE-2016-1631](#cve-2016-1631)
- [CVE-2016-1646](#cve-2016-1646)
- [CVE-2016-1653](#cve-2016-1653)
- [CVE-2016-1665](#cve-2016-1665)
- [CVE-2016-1667](#cve-2016-1667)
- [CVE-2016-1668](#cve-2016-1668)
- [CVE-2016-1669](#cve-2016-1669)
- [CVE-2016-1672](#cve-2016-1672)
- [CVE-2016-1673](#cve-2016-1673)
- [CVE-2016-1674](#cve-2016-1674)
- [CVE-2016-1675](#cve-2016-1675)
- [CVE-2016-1676](#cve-2016-1676)
- [CVE-2016-1677](#cve-2016-1677)
- [CVE-2016-1688](#cve-2016-1688)
- [CVE-2016-1697](#cve-2016-1697)
- [CVE-2016-1710](#cve-2016-1710)
- [CVE-2016-1711](#cve-2016-1711)
- [CVE-2016-1779](#cve-2016-1779)
- [CVE-2016-1857](#cve-2016-1857)
- [CVE-2016-1910](#cve-2016-1910)
- [CVE-2016-2384](#cve-2016-2384)
- [CVE-2016-2386](#cve-2016-2386)
- [CVE-2016-2388](#cve-2016-2388)
- [CVE-2016-3087](#cve-2016-3087)
- [CVE-2016-3088](#cve-2016-3088)
- [CVE-2016-3309](#cve-2016-3309)
- [CVE-2016-3714](#cve-2016-3714)
- [CVE-2016-3371](#cve-2016-3371)
- [CVE-2016-3386](#cve-2016-3386)
- [CVE-2016-4338](#cve-2016-4338)
- [CVE-2016-4437](#cve-2016-4437)
- [CVE-2016-4622](#cve-2016-4622)
- [CVE-2016-4734](#cve-2016-4734)
- [CVE-2016-4971](#cve-2016-4971)
- [CVE-2016-5129](#cve-2016-5129)
- [CVE-2016-5172](#cve-2016-5172)
- [CVE-2016-5195](#cve-2016-5195)
- [CVE-2016-5198](#cve-2016-5198)
- [CVE-2016-5200](#cve-2016-5200)
- [CVE-2016-5204](#cve-2016-5204)
- [CVE-2016-5207](#cve-2016-5207)
- [CVE-2016-5208](#cve-2016-5208)
- [CVE-2016-5346](#cve-2016-5346)
- [CVE-2016-5610](#cve-2016-5610)
- [CVE-2016-5611](#cve-2016-5611)
- [CVE-2016-5734](#cve-2016-5734)
- [CVE-2016-6210](#cve-2016-6210)
- [CVE-2016-6277](#cve-2016-6277)
- [CVE-2016-6415](#cve-2016-6415)
- [CVE-2016-6662](#cve-2016-6662)
- [CVE-2016-6700](#cve-2016-6700)
- [CVE-2016-6702](#cve-2016-6702)
- [CVE-2016-6762](#cve-2016-6762)
- [CVE-2016-6787](#cve-2016-6787)
- [CVE-2016-7124](#cve-2016-7124)
- [CVE-2016-7189](#cve-2016-7189)
- [CVE-2016-7190](#cve-2016-7190)
- [CVE-2016-7194](#cve-2016-7194)
- [CVE-2016-7200](#cve-2016-7200)
- [CVE-2016-7201](#cve-2016-7201)
- [CVE-2016-7202](#cve-2016-7202)
- [CVE-2016-7203](#cve-2016-7203)
- [CVE-2016-7240](#cve-2016-7240)
- [CVE-2016-7241](#cve-2016-7241)
- [CVE-2016-7255](#cve-2016-7255)
- [CVE-2016-7286](#cve-2016-7286)
- [CVE-2016-7287](#cve-2016-7287)
- [CVE-2016-7288](#cve-2016-7288)
- [CVE-2016-7547](#cve-2016-7547)
- [CVE-2016-7552](#cve-2016-7552)
- [CVE-2016-8413](#cve-2016-8413)
- [CVE-2016-8477](#cve-2016-8477)
- [CVE-2016-8584](#cve-2016-8584)
- [CVE-2016-8585](#cve-2016-8585)
- [CVE-2016-8586](#cve-2016-8586)
- [CVE-2016-8587](#cve-2016-8587)
- [CVE-2016-8588](#cve-2016-8588)
- [CVE-2016-8589](#cve-2016-8589)
- [CVE-2016-8590](#cve-2016-8590)
- [CVE-2016-8591](#cve-2016-8591)
- [CVE-2016-8592](#cve-2016-8592)
- [CVE-2016-8593](#cve-2016-8593)
- [CVE-2016-9651](#cve-2016-9651)
- [CVE-2016-9793](#cve-2016-9793)
- [CVE-2016-10033](#cve-2016-10033)
- [CVE-2016-10191](#cve-2016-10191)
- [CVE-2016-10277](#cve-2016-10277)
- [CVE-2016-10370](#cve-2016-10370)
- [CVE-2017-0015](#cve-2017-0015)
- [CVE-2017-0037](#cve-2017-0037)
- [CVE-2017-0059](#cve-2017-0059)
- [CVE-2017-0070](#cve-2017-0070)
- [CVE-2017-0071](#cve-2017-0071)
- [CVE-2017-0134](#cve-2017-0134)
- [CVE-2017-0135](#cve-2017-0135)
- [CVE-2017-0141](#cve-2017-0141)
- [CVE-2017-0143](#cve-2017-0143)
- [CVE-2017-0144](#cve-2017-0144)
- [CVE-2017-0145](#cve-2017-0145)
- [CVE-2017-0146](#cve-2017-0146)
- [CVE-2017-0147](#cve-2017-0147)
- [CVE-2017-0148](#cve-2017-0148)
- [CVE-2017-0199](#cve-2017-0199)
- [CVE-2017-0213](#cve-2017-0213)
- [CVE-2017-0234](#cve-2017-0234)
- [CVE-2017-0236](#cve-2017-0236)
- [CVE-2017-0263](#cve-2017-0263)
- [CVE-2017-0283](#cve-2017-0283)
- [CVE-2017-0290](#cve-2017-0290)
- [CVE-2017-0392](#cve-2017-0392)
- [CVE-2017-0474](#cve-2017-0474)
- [CVE-2017-0475](#cve-2017-0475)
- [CVE-2017-0497](#cve-2017-0497)
- [CVE-2017-0521](#cve-2017-0521)
- [CVE-2017-0531](#cve-2017-0531)
- [CVE-2017-0541](#cve-2017-0541)
- [CVE-2017-0548](#cve-2017-0548)
- [CVE-2017-0576](#cve-2017-0576)
- [CVE-2017-0641](#cve-2017-0641)
- [CVE-2017-0678](#cve-2017-0678)
- [CVE-2017-0714](#cve-2017-0714)
- [CVE-2017-0718](#cve-2017-0718)
- [CVE-2017-0719](#cve-2017-0719)
- [CVE-2017-0720](#cve-2017-0720)
- [CVE-2017-0722](#cve-2017-0722)
- [CVE-2017-0745](#cve-2017-0745)
- [CVE-2017-0758](#cve-2017-0758)
- [CVE-2017-0760](#cve-2017-0760)
- [CVE-2017-0761](#cve-2017-0761)
- [CVE-2017-0764](#cve-2017-0764)
- [CVE-2017-0776](#cve-2017-0776)
- [CVE-2017-0777](#cve-2017-0777)
- [CVE-2017-0778](#cve-2017-0778)
- [CVE-2017-0781](#cve-2017-0781)
- [CVE-2017-0785](#cve-2017-0785)
- [CVE-2017-0813](#cve-2017-0813)
- [CVE-2017-0814](#cve-2017-0814)
- [CVE-2017-0820](#cve-2017-0820)
- [CVE-2017-1082](#cve-2017-1082)
- [CVE-2017-1083](#cve-2017-1083)
- [CVE-2017-1084](#cve-2017-1084)
- [CVE-2017-1085](#cve-2017-1085)
- [CVE-2017-2363](#cve-2017-2363)
- [CVE-2017-2364](#cve-2017-2364)
- [CVE-2017-2365](#cve-2017-2365)
- [CVE-2017-2367](#cve-2017-2367)
- [CVE-2017-2416](#cve-2017-2416)
- [CVE-2017-2419](#cve-2017-2419)
- [CVE-2017-2426](#cve-2017-2426)
- [CVE-2017-2442](#cve-2017-2442)
- [CVE-2017-2445](#cve-2017-2445)
- [CVE-2017-2446](#cve-2017-2446)
- [CVE-2017-2447](#cve-2017-2447)
- [CVE-2017-2460](#cve-2017-2460)
- [CVE-2017-2464](#cve-2017-2464)
- [CVE-2017-2468](#cve-2017-2468)
- [CVE-2017-2475](#cve-2017-2475)
- [CVE-2017-2479](#cve-2017-2479)
- [CVE-2017-2480](#cve-2017-2480)
- [CVE-2017-2491](#cve-2017-2491)
- [CVE-2017-2493](#cve-2017-2493)
- [CVE-2017-2504](#cve-2017-2504)
- [CVE-2017-2508](#cve-2017-2508)
- [CVE-2017-2510](#cve-2017-2510)
- [CVE-2017-2521](#cve-2017-2521)
- [CVE-2017-2528](#cve-2017-2528)
- [CVE-2017-2531](#cve-2017-2531)
- [CVE-2017-2536](#cve-2017-2536)
- [CVE-2017-2540](#cve-2017-2540)
- [CVE-2017-2541](#cve-2017-2540)
- [CVE-2017-2547](#cve-2017-2547)
- [CVE-2017-2636](#cve-2017-2636)
- [CVE-2017-2641](#cve-2017-2641)
- [CVE-2017-3066](#cve-2017-3066)
- [CVE-2017-3248](#cve-2017-3248)
- [CVE-2017-3506](#cve-2017-3506)
- [CVE-2017-3599](#cve-2017-3599)
- [CVE-2017-3629](#cve-2017-3629)
- [CVE-2017-3630](#cve-2017-3630)
- [CVE-2017-3631](#cve-2017-3631)
- [CVE-2017-3881](#cve-2017-3881)
- [CVE-2017-4901](#CVE-2017-4901)
- [CVE-2017-4914](#cve-2017-4914)
- [CVE-2017-4915](#cve-2017-4915)
- [CVE-2017-4918](#cve-2017-4918)
- [CVE-2017-4933](#cve-2017-4933)
- [CVE-2017-4946](#cve-2017-4946)
- [CVE-2017-4971](#cve-2017-4971)
- [CVE-2017-5007](#cve-2017-5007)
- [CVE-2017-5008](#cve-2017-5008)
- [CVE-2017-5010](#cve-2017-5010)
- [CVE-2017-5030](#cve-2017-5030)
- [CVE-2017-5033](#cve-2017-5033)
- [CVE-2017-5040](#cve-2017-5040)
- [CVE-2017-5053](#cve-2017-5053)
- [CVE-2017-5070](#cve-2017-5070)
- [CVE-2017-5071](#cve-2017-5071)
- [CVE-2017-5088](#cve-2017-5088)
- [CVE-2017-5098](#cve-2017-5098)
- [CVE-2017-5115](#cve-2017-5115)
- [CVE-2017-5116](#cve-2017-5116)
- [CVE-2017-5121](#cve-2017-5121)
- [CVE-2017-5122](#cve-2017-5122)
- [CVE-2017-5123](#cve-2017-5123)
- [CVE-2017-5124](#cve-2017-5124)
- [CVE-2017-5126](#cve-2017-5126)
- [CVE-2017-5127](#cve-2017-5127)
- [CVE-2017-5128](#cve-2017-5128)
- [CVE-2017-5129](#cve-2017-5129)
- [CVE-2017-5133](#cve-2017-5133)
- [CVE-2017-5135](#cve-2017-5135)
- [CVE-2017-5622](#cve-2017-5622)
- [CVE-2017-5624](#cve-2017-5624)
- [CVE-2017-5626](#cve-2017-5626)
- [CVE-2017-5638](#cve-2017-5638)
- [CVE-2017-5641](#cve-2017-5641)
- [CVE-2017-5689](#cve-2017-5689)
- [CVE-2017-5715](#cve-2017-5715)
- [CVE-2017-5753](#cve-2017-5753)
- [CVE-2017-5754](#cve-2017-5754)
- [CVE-2017-5891](#cve-2017-5891)
- [CVE-2017-5892](#cve-2017-5892)
- [CVE-2017-5948](#cve-2017-5948)
- [CVE-2017-6008](#cve-2017-6008)
- [CVE-2017-6074](#cve-2017-6074)
- [CVE-2017-6178](#cve-2017-6178)
- [CVE-2017-6198](#cve-2017-6198)
- [CVE-2017-6199](#cve-2017-6199)
- [CVE-2017-6200](#cve-2017-6200)
- [CVE-2017-6201](#cve-2017-6201)
- [CVE-2017-6326](#cve-2017-6326)
- [CVE-2017-6327](#cve-2017-6327)
- [CVE-2017-6736](#cve-2017-6736)
- [CVE-2017-6980](#cve-2017-6980)
- [CVE-2017-6984](#cve-2017-6984)
- [CVE-2017-7037](#cve-2017-7037)
- [CVE-2017-7056](#cve-2017-7056)
- [CVE-2017-7061](#cve-2017-7061)
- [CVE-2017-7089](#cve-2017-7089)
- [CVE-2017-7092](#cve-2017-7092)
- [CVE-2017-7115](#cve-2017-7115)
- [CVE-2017-7117](#cve-2017-7117)
- [CVE-2017-7150](#cve-2017-7150)
- [CVE-2017-7219](#cve-2017-7219)
- [CVE-2017-7269](#cve-2017-7269)
- [CVE-2017-7279](#cve-2017-7279)
- [CVE-2017-7280](#cve-2017-7280)
- [CVE-2017-7281](#cve-2017-7281)
- [CVE-2017-7281](#cve-2017-7282)
- [CVE-2017-7281](#cve-2017-7283)
- [CVE-2017-7293](#cve-2017-7293)
- [CVE-2017-7308](#cve-2017-7308)
- [CVE-2017-7344](#cve-2017-7344)
- [CVE-2017-7442](#cve-2017-7442)
- [CVE-2017-7494](#cve-2017-7494)
- [CVE-2017-7504](#cve-2017-7504)
- [CVE-2017-7525](#cve-2017-7525)
- [CVE-2017-7529](#cve-2017-7529)
- [CVE-2017-7533](#cve-2017-7533)
- [CVE-2017-8046](#cve-2017-8046)
- [CVE-2017-8291](#cve-2017-8291)
- [CVE-2017-8295](#cve-2017-8295)
- [CVE-2017-8386](#cve-2017-8386)
- [CVE-2017-8464](#cve-2017-8464)
- [CVE-2017-8514](#cve-2017-8514)
- [CVE-2017-8543](#cve-2017-8543)
- [CVE-2017-8548](#cve-2017-8548)
- [CVE-2017-8570](#cve-2017-8570)
- [CVE-2017-8601](#cve-2017-8601)
- [CVE-2017-8625](#cve-2017-8625)
- [CVE-2017-8634](#cve-2017-8634)
- [CVE-2017-8636](#cve-2017-8636)
- [CVE-2017-8640](#cve-2017-8640)
- [CVE-2017-8645](#cve-2017-8645)
- [CVE-2017-8646](#cve-2017-8646)
- [CVE-2017-8656](#cve-2017-8656)
- [CVE-2017-8670](#cve-2017-8670)
- [CVE-2017-8671](#cve-2017-8671)
- [CVE-2017-8729](#cve-2017-8729)
- [CVE-2017-8740](#cve-2017-8740)
- [CVE-2017-8751](#cve-2017-8751)
- [CVE-2017-8755](#cve-2017-8755)
- [CVE-2017-8759](#cve-2017-8759)
- [CVE-2017-8817](#cve-2017-8817)
- [CVE-2017-8850](#cve-2017-8850)
- [CVE-2017-8851](#cve-2017-8851)
- [CVE-2017-8877](#cve-2017-8877)
- [CVE-2017-8878](#cve-2017-8878)
- [CVE-2017-8890](#cve-2017-8890)
- [CVE-2017-8912](#cve-2017-8912)
- [CVE-2017-8917](#cve-2017-8917)
- [CVE-2017-9417](#cve-2017-9417)
- [CVE-2017-9791](#cve-2017-9791)
- [CVE-2017-9798](#cve-2017-9798)
- [CVE-2017-9805](#cve-2017-9805)
- [CVE-2017-9822](#cve-2017-9822)
- [CVE-2017-9948](#cve-2017-9948)
- [CVE-2017-9993](#cve-2017-9993)
- [CVE-2017-10271](#cve-2017-10271)
- [CVE-2017-10661](#cve-2017-10661)
- [CVE-2017-11105](#cve-2017-11105)
- [CVE-2017-11120](#cve-2017-11120)
- [CVE-2017-11421](#cve-2017-11421)
- [CVE-2017-11444](#cve-2017-11444)
- [CVE-2017-11610](#cve-2017-11610)
- [CVE-2017-11764](#cve-2017-11764)
- [CVE-2017-11774](#cve-2017-11774)
- [CVE-2017-11779](#cve-2017-11779)
- [CVE-2017-11793](#cve-2017-11793)
- [CVE-2017-11799](#cve-2017-11799)
- [CVE-2017-11802](#cve-2017-11802)
- [CVE-2017-11809](#cve-2017-11809)
- [CVE-2017-11811](#cve-2017-11811)
- [CVE-2017-11812](#CVE-2017-11812)
- [CVE-2017-11839](#cve-2017-11839)
- [CVE-2017-11840](#cve-2017-11840)
- [CVE-2017-11841](#cve-2017-11841)
- [CVE-2017-11855](#cve-2017-11855)
- [CVE-2017-11861](#cve-2017-11861)
- [CVE-2017-11870](#cve-2017-11870)
- [CVE-2017-11873](#cve-2017-11873)
- [CVE-2017-11882](#cve-2017-11882)
- [CVE-2017-11890](#cve-2017-11890)
- [CVE-2017-11893](#cve-2017-11893)
- [CVE-2017-11903](#cve-2017-11903)
- [CVE-2017-11906](#cve-2017-11906)
- [CVE-2017-11907](#cve-2017-11907)
- [CVE-2017-11909](#cve-2017-11909)
- [CVE-2017-11911](#cve-2017-11911)
- [CVE-2017-11914](#cve-2017-11914)
- [CVE-2017-11918](#cve-2017-11918)
- [CVE-2017-12097](#cve-2017-12097)
- [CVE-2017-12098](#cve-2017-12098)
- [CVE-2017-12149](#cve-2017-12149)
- [CVE-2017-12542](#cve-2017-12542)
- [CVE-2017-12581](#cve-2017-12581)
- [CVE-2017-12611](#cve-2017-12611)
- [CVE-2017-12615](#cve-2017-12615)
- [CVE-2017-12617](#cve-2017-12617)
- [CVE-2017-13089](#cve-2017-13089)
- [CVE-2017-13156](#cve-2017-13156)
- [CVE-2017-13253](#cve-2017-13253)
- [CVE-2017-13258](#cve-2017-13258)
- [CVE-2017-13260](#cve-2017-13260)
- [CVE-2017-13261](#cve-2017-13261)
- [CVE-2017-13262](#cve-2017-13262)
- [CVE-2017-13791](#cve-2017-13791)
- [CVE-2017-13792](#cve-2017-13792)
- [CVE-2017-14135](#cve-2017-14135)
- [CVE-2017-14335](#cve-2017-14335)
- [CVE-2017-14491](#cve-2017-14491)
- [CVE-2017-14492](#cve-2017-14492)
- [CVE-2017-14493](#cve-2017-14493)
- [CVE-2017-14494](#cve-2017-14494)
- [CVE-2017-14495](#cve-2017-14495)
- [CVE-2017-14496](#cve-2017-14496)
- [CVE-2017-14904](#cve-2017-14904)
- [CVE-2017-15277](#cve-2017-15277)
- [CVE-2017-15303](#cve-2017-15303)
- [CVE-2017-15361](#cve-2017-15361)
- [CVE-2017-15388](#cve-2017-15388)
- [CVE-2017-15396](#cve-2017-15396)
- [CVE-2017-15398](#cve-2017-15398)
- [CVE-2017-15399](#cve-2017-15399)
- [CVE-2017-15401](#cve-2017-15401)
- [CVE-2017-15411](#cve-2017-15411)
- [CVE-2017-15412](#cve-2017-15412)
- [CVE-2017-15415](#cve-2017-15415)
- [CVE-2017-15428](#cve-2017-15428)
- [CVE-2017-15613](#cve-2017-15613)
- [CVE-2017-15614](#cve-2017-15614)
- [CVE-2017-15615](#cve-2017-15615)
- [CVE-2017-15616](#cve-2017-15616)
- [CVE-2017-15617](#cve-2017-15617)
- [CVE-2017-15618](#cve-2017-15618)
- [CVE-2017-15619](#cve-2017-15619)
- [CVE-2017-15620](#cve-2017-15620)
- [CVE-2017-15621](#cve-2017-15621)
- [CVE-2017-15622](#cve-2017-15622)
- [CVE-2017-15623](#cve-2017-15623)
- [CVE-2017-15624](#cve-2017-15624)
- [CVE-2017-15625](#cve-2017-15625)
- [CVE-2017-15626](#cve-2017-15626)
- [CVE-2017-15627](#cve-2017-15627)
- [CVE-2017-15628](#cve-2017-15628)
- [CVE-2017-15629](#cve-2017-15629)
- [CVE-2017-15630](#cve-2017-15630)
- [CVE-2017-15631](#cve-2017-15631)
- [CVE-2017-15632](#cve-2017-15632)
- [CVE-2017-15633](#cve-2017-15633)
- [CVE-2017-15634](#cve-2017-15634)
- [CVE-2017-15635](#cve-2017-15635)
- [CVE-2017-15636](#cve-2017-15636)
- [CVE-2017-15637](#cve-2017-15637)
- [CVE-2017-15944](#cve-2017-15944)
- [CVE-2017-16544](#cve-2017-16544)
- [CVE-2017-16584](#cve-2017-16584)
- [CVE-2017-16716](#cve-2017-16716)
- [CVE-2017-16943](#cve-2017-16943)
- [CVE-2017-16944](#cve-2017-16944)
- [CVE-2017-16995](#cve-2017-16995)
- [CVE-2017-17033](#cve-2017-17033)
- [CVE-2017-17107](#cve-2017-17107)
- [CVE-2017-17215](#cve-2017-17215)
- [CVE-2017-17405](#cve-2017-17405)
- [CVE-2017-17408](#cve-2017-17408)
- [CVE-2017-17562](#cve-2017-17562)
- [CVE-2017-17692](#cve-2017-17692)
- [CVE-2017-17867](#cve-2017-17867)
- [CVE-2017-17969](#cve-2017-17969)
- [CVE-2017-18344](#cve-2017-18344)
- [CVE-2017-1000112](#cve-2017-1000112)
- [CVE-2017-1000117](#cve-2017-1000117)
- [CVE-2017-1000251](#cve-2017-1000251)
- [CVE-2017-1000353](#cve-2017-1000353)
- [CVE-2017-1000364](#cve-2017-1000364)
- [CVE-2017-1000365](#cve-2017-1000365)
- [CVE-2017-1000366](#cve-2017-1000366)
- [CVE-2017-1000367](#cve-2017-1000367)
- [CVE-2017-1000369](#cve-2017-1000369)
- [CVE-2017-1000370](#cve-2017-1000370)
- [CVE-2017-1000371](#cve-2017-1000371)
- [CVE-2017-1000372](#cve-2017-1000372)
- [CVE-2017-1000373](#cve-2017-1000373)
- [CVE-2017-1000374](#cve-2017-1000374)
- [CVE-2017-1000375](#cve-2017-1000375)
- [CVE-2017-1000376](#cve-2017-1000376)
- [CVE-2017-1000377](#cve-2017-1000377)
- [CVE-2017-1000378](#cve-2017-1000378)
- [CVE-2017-1000379](#cve-2017-1000379)
- [CVE-2017-1000405](#cve-2017-1000405)
- [CVE-2017-1000424](#cve-2017-1000424)
- [CVE-2017-1000459](#cve-2017-1000459)
- [CVE-2017-1002101](#cve-2017-1002101)
- [CVE-2018-0101](#cve-2018-0101)
- [CVE-2018-0114](#cve-2018-0114)
- [CVE-2018-0171](#cve-2018-0171)
- [CVE-2018-0296](#cve-2018-0296)
- [CVE-2018-0492](#cve-2018-0492)
- [CVE-2018-0497](#cve-2018-0497)
- [CVE-2018-0498](#cve-2018-0498)
- [CVE-2018-0743](#cve-2018-0743)
- [CVE-2018-0744](#cve-2018-0744)
- [CVE-2018-0752](#cve-2018-0752)
- [CVE-2018-0758](#cve-2018-0758)
- [CVE-2018-0763](#cve-2018-0763)
- [CVE-2018-0767](#cve-2018-0767)
- [CVE-2018-0769](#cve-2018-0769)
- [CVE-2018-0770](#cve-2018-0770)
- [CVE-2018-0774](#cve-2018-0774)
- [CVE-2018-0775](#cve-2018-0775)
- [CVE-2018-0776](#cve-2018-0776)
- [CVE-2018-0777](#cve-2018-0777)
- [CVE-2018-0780](#cve-2018-0780)
- [CVE-2018-0797](#cve-2018-0797)
- [CVE-2018-0802](#cve-2018-0802)
- [CVE-2018-0824](#cve-2018-0824)
- [CVE-2018-0833](#cve-2018-0833)
- [CVE-2018-0834](#cve-2018-0834)
- [CVE-2018-0835](#cve-2018-0835)
- [CVE-2018-0837](#cve-2018-0837)
- [CVE-2018-0838](#cve-2018-0838)
- [CVE-2018-0840](#cve-2018-0840)
- [CVE-2018-0860](#cve-2018-0860)
- [CVE-2018-0871](#cve-2018-0871)
- [CVE-2018-0878](#cve-2018-0878)
- [CVE-2018-0886](#cve-2018-0886)
- [CVE-2018-0891](#cve-2018-0891)
- [CVE-2018-0933](#cve-2018-0933)
- [CVE-2018-0934](#cve-2018-0934)
- [CVE-2018-0935](#cve-2018-0935)
- [CVE-2018-0953](#cve-2018-0953)
- [CVE-2018-0980](#cve-2018-0980)
- [CVE-2018-1036](#cve-2018-1036)
- [CVE-2018-1037](#cve-2018-1037)
- [CVE-2018-1038](#cve-2018-1038)
- [CVE-2018-1040](#cve-2018-1040)
- [CVE-2018-1111](#cve-2018-1111)
- [CVE-2018-1149](#cve-2018-1149)
- [CVE-2018-1150](#cve-2018-1150)
- [CVE-2018-1207](#cve-2018-1207)
- [CVE-2018-1270](#cve-2018-1270)
- [CVE-2018-1273](#cve-2018-1273)
- [CVE-2018-1275](#cve-2018-1275)
- [CVE-2018-1335](#cve-2018-1335)
- [CVE-2018-1435](#cve-2018-1435)
- [CVE-2018-2628](#cve-2018-2628)
- [CVE-2018-2694](#cve-2018-2694)
- [CVE-2018-2698](#cve-2018-2698)
- [CVE-2018-2844](#cve-2018-2844)
- [CVE-2018-2860](#cve-2018-2860)
- [CVE-2018-2893](#cve-2018-2893)
- [CVE-2018-2894](#cve-2018-2894)
- [CVE-2018-3055](#cve-2018-3055)
- [CVE-2018-3085](#cve-2018-3085)
- [CVE-2018-3191](#cve-2018-3191)
- [CVE-2018-3245](#cve-2018-3245)
- [CVE-2018-3253](#cve-2018-3253)
- [CVE-2018-3615](#cve-2018-3615)
- [CVE-2018-3693](#cve-2018-3693)
- [CVE-2018-3760](#cve-2018-3760)
- [CVE-2018-3784](#cve-2018-3784)
- [CVE-2018-3893](#cve-2018-3893)
- [CVE-2018-3894](#cve-2018-3894)
- [CVE-2018-3895](#cve-2018-3895)
- [CVE-2018-3896](#cve-2018-3896)
- [CVE-2018-3897](#cve-2018-3897)
- [CVE-2018-3903](#cve-2018-3903)
- [CVE-2018-3904](#cve-2018-3904)
- [CVE-2018-3905](#cve-2018-3905)
- [CVE-2018-3952](#cve-2018-3952)
- [CVE-2018-3971](#cve-2018-3971)
- [CVE-2018-4087](#cve-2018-4087)
- [CVE-2018-4010](#cve-2018-4010)
- [CVE-2018-4121](#cve-2018-4121)
- [CVE-2018-4148](#cve-2018-4148)
- [CVE-2018-4150](#cve-2018-4150)
- [CVE-2018-4192](#cve-2018-4192)
- [CVE-2018-4204](#cve-2018-4204)
- [CVE-2018-4233](#cve-2018-4233)
- [CVE-2018-4262](#cve-2018-4262)
- [CVE-2018-4307](#cve-2018-4307)
- [CVE-2018-4330](#cve-2018-4330)
- [CVE-2018-4338](#cve-2018-4338)
- [CVE-2018-4407](#cve-2018-4407)
- [CVE-2018-4415](#cve-2018-4415)
- [CVE-2018-4878](#cve-2018-4878)
- [CVE-2018-4990](#cve-2018-4990)
- [CVE-2018-4993](#cve-2018-4993)
- [CVE-2018-5002](#cve-2018-5002)
- [CVE-2018-5146](#cve-2018-5146)
- [CVE-2018-5175](#cve-2018-5175)
- [CVE-2018-5181](#cve-2018-5181)
- [CVE-2018-5189](#cve-2018-5189)
- [CVE-2018-5318](#cve-2018-5318)
- [CVE-2018-5390](#cve-2018-5390)
- [CVE-2018-5553](#cve-2018-5553)
- [CVE-2018-5711](#cve-2018-5711)
- [CVE-2018-5924](#cve-2018-5924)
- [CVE-2018-5925](#cve-2018-5925)
- [CVE-2018-5996](#cve-2018-5996)
- [CVE-2018-6034](#cve-2018-6034)
- [CVE-2018-6055](#cve-2018-6055)
- [CVE-2018-6056](#cve-2018-6056)
- [CVE-2018-6061](#cve-2018-6061)
- [CVE-2018-6064](#cve-2018-6064)
- [CVE-2018-6065](#cve-2018-6065)
- [CVE-2018-6072](#cve-2018-6072)
- [CVE-2018-6106](#cve-2018-6106)
- [CVE-2018-6128](#cve-2018-6128)
- [CVE-2018-6177](#cve-2018-6177)
- [CVE-2018-6184](#cve-2018-6184)
- [CVE-2018-6317](#cve-2018-6317)
- [CVE-2018-6376](#cve-2018-6376)
- [CVE-2018-6389](#cve-2018-6389)
- [CVE-2018-6460](#cve-2018-6460)
- [CVE-2018-6789](#cve-2018-6789)
- [CVE-2018-6794](#cve-2018-6794)
- [CVE-2018-6851](#cve-2018-6851)
- [CVE-2018-6852](#cve-2018-6852)
- [CVE-2018-6853](#cve-2018-6853)
- [CVE-2018-6854](#cve-2018-6854)
- [CVE-2018-6855](#cve-2018-6855)
- [CVE-2018-6856](#cve-2018-6856)
- [CVE-2018-6857](#cve-2018-6857)
- [CVE-2018-6871](#cve-2018-6871)
- [CVE-2018-6954](#cve-2018-6954)
- [CVE-2018-7182](#cve-2018-7182)
- [CVE-2018-7260](#cve-2018-7260)
- [CVE-2018-7273](#cve-2018-7273)
- [CVE-2018-7600](#cve-2018-7600)
- [CVE-2018-7602](#cve-2018-7602)
- [CVE-2018-7738](#cve-2018-7738)
- [CVE-2018-8021](#cve-2018-8021)
- [CVE-2018-8120](#cve-2018-8120)
- [CVE-2018-8140](#cve-2018-8140)
- [CVE-2018-8174](#cve-2018-8174)
- [CVE-2018-8212](#cve-2018-8212)
- [CVE-2018-8235](#cve-2018-8235)
- [CVE-2018-8367](#cve-2018-8367)
- [CVE-2018-8373](#cve-2018-8373)
- [CVE-2018-8383](#cve-2018-8383)
- [CVE-2018-8414](#cve-2018-8414)
- [CVE-2018-8420](#cve-2018-8420)
- [CVE-2018-8440](#cve-2018-8440)
- [CVE-2018-8495](#cve-2018-8495)
- [CVE-2018-8532](#cve-2018-8532)
- [CVE-2018-8589](#cve-2018-8589)
- [CVE-2018-8611](#cve-2018-8611)
- [CVE-2018-8639](#cve-2018-8639)
- [CVE-2018-8719](#cve-2018-8719)
- [CVE-2018-8733](#cve-2018-8733)
- [CVE-2018-8734](#cve-2018-8734)
- [CVE-2018-8735](#cve-2018-8735)
- [CVE-2018-8736](#cve-2018-8736)
- [CVE-2018-8778](#cve-2018-8778)
- [CVE-2018-8819](#cve-2018-8819)
- [CVE-2018-8897](#cve-2018-8897)
- [CVE-2018-8955](#cve-2018-8955)
- [CVE-2018-9206](#cve-2018-9206)
- [CVE-2018-9341](#cve-2018-9341)
- [CVE-2018-9359](#cve-2018-9359)
- [CVE-2018-9360](#cve-2018-9360)
- [CVE-2018-9361](#cve-2018-9361)
- [CVE-2018-9411](#cve-2018-9411)
- [CVE-2018-9445](#cve-2018-9445)
- [CVE-2018-9995](#cve-2018-9995)
- [CVE-2018-10115](#cve-2018-10115)
- [CVE-2018-10172](#cve-2018-10172)
- [CVE-2018-10468](#cve-2018-10468)
- [CVE-2018-10561](#cve-2018-10561)
- [CVE-2018-10562](#cve-2018-10562)
- [CVE-2018-10641](#cve-2018-10641)
- [CVE-2018-10666](#cve-2018-10666)
- [CVE-2018-10676](#cve-2018-10676)
- [CVE-2018-10895](#cve-2018-10895)
- [CVE-2018-10933](#cve-2018-10933)
- [CVE-2018-10944](#cve-2018-10944)
- [CVE-2018-10956](#cve-2018-10956)
- [CVE-2018-10994](#cve-2018-10994)
- [CVE-2018-11101](#cve-2018-11101)
- [CVE-2018-11235](#cve-2018-11235)
- [CVE-2018-11411](#cve-2018-11411)
- [CVE-2018-11689](#cve-2018-11689)
- [CVE-2018-11759](#cve-2018-11759)
- [CVE-2018-11776](#cve-2018-11776)
- [CVE-2018-11784](#cve-2018-11784)
- [CVE-2018-11788](#cve-2018-11788)
- [CVE-2018-11882](#cve-2018-11882)
- [CVE-2018-12015](#cve-2018-12015)
- [CVE-2018-12020](#cve-2018-12020)
- [CVE-2018-12034](#cve-2018-12034)
- [CVE-2018-12035](#cve-2018-12035)
- [CVE-2018-12056](#cve-2018-12056)
- [CVE-2018-12386](#cve-2018-12386)
- [CVE-2018-12387](#cve-2018-12387)
- [CVE-2018-12454](#cve-2018-12454)
- [CVE-2018-12885](#cve-2018-12885)
- [CVE-2018-13149](#cve-2018-13149)
- [CVE-2018-13452](#cve-2018-13452)
- [CVE-2018-14327](#cve-2018-14327)
- [CVE-2018-14634](#cve-2018-14634)
- [CVE-2018-14665](#cve-2018-14665)
- [CVE-2018-14667](#cve-2018-14667)
- [CVE-2018-14686](#cve-2018-14686)
- [CVE-2018-14715](#cve-2018-14715)
- [CVE-2018-14847](#cve-2018-14847)
- [CVE-2018-15473](#cve-2018-15473)
- [CVE-2018-15685](#cve-2018-15685)
- [CVE-2018-15705](#cve-2018-15705)
- [CVE-2018-15706](#cve-2018-15706)
- [CVE-2018-15707](#cve-2018-15707)
- [CVE-2018-15715](#cve-2018-15715)
- [CVE-2018-15869](#cve-2018-15869)
- [CVE-2018-15961](#cve-2018-15961)
- [CVE-2018-15982](#cve-2018-15982)
- [CVE-2018-16323](#cve-2018-16323)
- [CVE-2018-16384](#cve-2018-16384)
- [CVE-2018-16509](#cve-2018-16509)
- [CVE-2018-16946](#cve-2018-16946)
- [CVE-2018-17082](#cve-2018-17082)
- [CVE-2018-17144](#cve-2018-17144)
- [CVE-2018-17182](#cve-2018-17182)
- [CVE-2018-17780](#cve-2018-17780)
- [CVE-2018-19276](#cve-2018-19276)
- [CVE-2018-19788](#cve-2018-19788)
- [CVE-2018-20250](#cve-2018-20250)
- [CVE-2018-20714](#cve-2018-20714)
- [CVE-2018-1000006](#cve-2018-1000006)
- [CVE-2018-1000094](#cve-2018-1000094)
- [CVE-2018-1000129](#cve-2018-1000129)
- [CVE-2018-1000130](#cve-2018-1000130)
- [CVE-2018-1000136](#cve-2018-1000136)
- [CVE-2018-1002105](#cve-2018-1002105)
- [CVE-2019-0193](#cve-2019-0193)
- [CVE-2019-0211](#cve-2019-0211)
- [CVE-2019-0232](#cve-2019-0232)
- [CVE-2019-0539](#cve-2019-0539)
- [CVE-2019-0604](#cve-2019-0604)
- [CVE-2019-0708](#cve-2019-0708)
- [CVE-2019-0797](#cve-2019-0797)
- [CVE-2019-0808](#cve-2019-0808)
- [CVE-2019-0841](#cve-2019-0841)
- [CVE-2019-1306](#cve-2019-1306)
- [CVE-2019-1388](#cve-2019-1388)
- [CVE-2019-1414](#cve-2019-1414)
- [CVE-2019-1458](#cve-2019-1458)
- [CVE-2019-2588](#cve-2019-2588)
- [CVE-2019-2618](#cve-2019-2618)
- [CVE-2019-2725](#cve-2019-2725)
- [CVE-2019-2888](#cve-2019-2888)
- [CVE-2019-2890](#cve-2019-2890)
- [CVE-2020-3187](#cve-2020-3187)
- [CVE-2019-3394](#cve-2019-3394)
- [CVE-2019-3396](#cve-2019-3396)
- [CVE-2019-3560](#cve-2019-3560)
- [CVE-2019-3921](#cve-2019-3921)
- [CVE-2019-5241](#cve-2019-5241)
- [CVE-2019-5418](#cve-2019-5418)
- [CVE-2019-5624](#cve-2019-5624)
- [CVE-2019-5736](#cve-2019-5736)
- [CVE-2019-5790](#cve-2019-5790)
- [CVE-2019-6251](#cve-2019-6251)
- [CVE-2019-7192](#cve-2019-7192)
- [CVE-2019-7193](#cve-2019-7193)
- [CVE-2019-7194](#cve-2019-7194)
- [CVE-2019-7195](#cve-2019-7195)
- [CVE-2019-7238](#cve-2019-7238)
- [CVE-2019-7286](#cve-2019-7286)
- [CVE-2019-7609](#cve-2019-7609)
- [CVE-2019-8451](#cve-2019-8451)
- [CVE-2019-8518](#cve-2019-8518)
- [CVE-2019-8565](#cve-2019-8565)
- [CVE-2019-9213](#cve-2019-9213)
- [CVE-2019-10038](#cve-2019-10038)
- [CVE-2019-10392](#cve-2019-10392)
- [CVE-2019-11043](#cve-2019-11043)
- [CVE-2019-11354](#cve-2019-11354)
- [CVE-2019-11358](#cve-2019-11358)
- [CVE-2019-11510](#cve-2019-11510)
- [CVE-2019-11580](#cve-2019-11580)
- [CVE-2019-11581](#cve-2019-11581)
- [CVE-2019-12384](#cve-2019-12384)
- [CVE-2019-12409](#cve-2019-12409)
- [CVE-2019-12415](#cve-2019-12415)
- [CVE-2019-12526](#cve-2019-12526)
- [CVE-2019-12527](#cve-2019-12527)
- [CVE-2019-13272](#cve-2019-13272)
- [CVE-2019-13720](#cve-2019-13720)
- [CVE-2019-14234](#cve-2019-14234)
- [CVE-2019-14994](#cve-2019-14994)
- [CVE-2019-15107](#cce-2019-15107)
- [CVE-2019-15126](#cve-2019-15126)
- [CVE-2019-15642](#cve-2019-15642)
- [CVE-2019-16278](#cve-2019-16278)
- [CVE-2019-16384](#cve-2019-16384)
- [CVE-2019-16385](#cve-2019-16385)
- [CVE-2019-16759](#cve-2019-16759)
- [CVE-2019-17564](#cve-2019-17564)
- [CVE-2019-18683](#cve-2019-18683)
- [CVE-2019-18935](#cve-2019-18935)
- [CVE-2019-19781](#cve-2019-19781)
- [CVE-2019-20197](#cve-2019-20197)
- [CVE-2020-0601](#cve-2020-0601)
- [CVE-2020-0609](#cve-2020-0609)
- [CVE-2020-0610](#cve-2020-0610)
- [CVE-2020-0668](#cve-2020-0668)
- [CVE-2020-0683](#cve-2020-0683)
- [CVE-2020-0688](#cve-2020-0688)
- [CVE-2020-0787](#cve-2020-0787)
- [CVE-2020-0796](#cve-2020-0796)
- [CVE-2020-0863](#cve-2020-0863)
- [CVE-2020-0932](#cve-2020-0932)
- [CVE-2020-0984](#cve-2020-0984)
- [CVE-2020-1181](#cve-2020-1181)
- [CVE-2020-1206](#cve-2020-1206)
- [CVE-2020-1938](#cve-2020-1938)
- [CVE-2020-2096](#cve-2020-2096)
- [CVE-2020-2551](#cve-2020-2551)
- [CVE-2020-2555](#cve-2020-2555)
- [CVE-2020-3452](#cve-2020-3452)
- [CVE-2020-3882](#cve-2020-3882)
- [CVE-2020-3950](#cve-2020-3950)
- [CVE-2020-3956](#cve-2020-3956)
- [CVE-2020-5398](#cve-2020-5398)
- [CVE-2020-5902](#cve-2020-5902)
- [CVE-2020-6418](#cve-2020-6418)
- [CVE-2020-7961](#cve-2020-7961)
- [CVE-2020-8840](#cve-2020-8840)
- [CVE-2020-9471](#cve-2020-9471)
- [CVE-2020-9472](#cve-2020-9472)
- [CVE-2020-9484](#cve-2020-9484)
- [CVE-2020-9546](#cve-2020-9546)
- [CVE-2020-9547](#cve-2020-9547)
- [CVE-2020-9548](#cve-2020-9548)
- [CVE-2020-10673](#cve-2020-10673)
- [CVE-2020-11108](#cve-2020-11108)
- [CVE-2020-11932](#cve-2020-11932)
- [CVE-2020-28948](#cve-2020-28948)
- [CVE-2020-28949](#cve-2020-28949)

## Resource

### [CVE-2011-2856](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2011-2856)

- Google V8, as used in Google Chrome before 14.0.835.163, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

### [CVE-2011-3243](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2011-3243)

- Cross-site scripting (XSS) vulnerability in WebKit, as used in Apple iOS before 5 and Safari before 5.1.1, allows remote attackers to inject arbitrary web script or HTML via vectors involving inactive DOM windows.

### [CVE-2013-2618](https://blog.trendmicro.com/trendlabs-security-intelligence/cryptocurrency-miner-distributed-via-php-weathermap-vulnerability-targets-linux-servers/)

- Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web script or HTML via the map_title parameter.

### [CVE-2013-6632](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2013-6632.md)

- Integer overflow in Google Chrome before 31.0.1650.57 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as demonstrated during a Mobile Pwn2Own competition at PacSec 2013.

### [CVE-2014-1701](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2014-1701)

- The GenerateFunction function in bindings/scripts/code_generator_v8.pm in Blink, as used in Google Chrome before 33.0.1750.149, does not implement a certain cross-origin restriction for the EventTarget::dispatchEvent function, which allows remote attackers to conduct Universal XSS (UXSS) attacks via vectors involving events.

### [CVE-2014-1705](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2014-1705.md)

- Google V8, as used in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

### [CVE-2014-1747](https://github.com/Metnew/uxss-db/blob/master/chrome/CVE-2014-1747)

- Cross-site scripting (XSS) vulnerability in the DocumentLoader::maybeCreateArchive function in core/loader/DocumentLoader.cpp in Blink, as used in Google Chrome before 35.0.1916.114, allows remote attackers to inject arbitrary web script or HTML via crafted MHTML content, aka "Universal XSS (UXSS)."

### [CVE-2014-3176](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2014-3176.md)

- Google Chrome before 37.0.2062.94 does not properly handle the interaction of extensions, IPC, the sync API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-3177.

### [CVE-2014-6332](https://gist.github.com/worawit/84ab41358b8465966224)

- OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."

### [CVE-2014-7927](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2014-7927.md)

- The SimplifiedLowering::DoLoadBuffer function in compiler/simplified-lowering.cc in Google V8, as used in Google Chrome before 40.0.2214.91, does not properly choose an integer data type, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.

### [CVE-2014-7928](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2014-7928.md)

- hydrogen.cc in Google V8, as used Google Chrome before 40.0.2214.91, does not properly handle arrays with holes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code that triggers an array copy.

### [CVE-2015-0072](https://github.com/dbellavista/uxss-poc)

- Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a second IFRAME element that does not trigger a redirect, and an eval of a WindowProxy object, aka "Universal XSS (UXSS)."

### [CVE-2015-0235](https://github.com/geekben/cve-collections/blob/master/cve20150235poc.c)

- Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST".

### [CVE-2015-0240](https://gist.github.com/worawit/051e881fc94fe4a49295)

- The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the ServerPasswordSet RPC API, as demonstrated by packets reaching the _netr_ServerPasswordSet function in rpc_server/netlogon/srv_netlog_nt.c.

### [CVE-2015-1233](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2015-1233.md)

- Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors.

### [CVE-2015-1242](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2015-1242.md)

- The ReduceTransitionElementsKind function in hydrogen-check-elimination.cc in Google V8 before 4.2.77.8, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that leverages "type confusion" in the check-elimination optimization.

### [CVE-2015-1268](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2015-1268)

- bindings/scripts/v8_types.py in Blink, as used in Google Chrome before 43.0.2357.130, does not properly select a creation context for a return value's DOM wrapper, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code, as demonstrated by use of a data: URL.

### [CVE-2015-1635](https://gist.github.com/worawit/54f2e5a7a1a028191f76)

- HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution Vulnerability."

### [CVE-2015-1830](https://github.com/ysrc/xunfeng/blob/master/vulscan/vuldb/activemq_upload.py)

- Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5.x before 5.11.2 for Windows allows remote attackers to create JSP files in arbitrary directories via unspecified vectors.

### [CVE-2015-2177](https://www.exploit-db.com/exploits/44802/)

- Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via crafted packets on (1) TCP port 102 or (2) Profibus.

### [CVE-2015-3306](https://www.exploit-db.com/exploits/36803/)

- The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

### [CVE-2015-5119](https://www.mdsec.co.uk/2018/02/adobe-flash-exploitation-then-and-now-from-cve-2015-5119-to-cve-2018-4878/)

- Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

### [CVE-2015-5254](https://github.com/jas502n/CVE-2015-5254)

- Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.

### [CVE-2015-5531](https://github.com/nixawk/labs/tree/master/CVE-2015-5531)

- Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.

### [CVE-2015-6086](https://github.com/payatu/CVE-2015-6086)

- Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

### [CVE-2015-6755](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2015-6755)

- The ContainerNode::parserInsertBefore function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 46.0.2490.71, proceeds with a DOM tree insertion in certain cases where a parent node no longer contains a child node, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

### [CVE-2015-6764](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2015-6764.md)

- The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

### [CVE-2015-6769](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2015-6769)

- The provisional-load commit implementation in WebKit/Source/bindings/core/v8/WindowProxy.cpp in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy by leveraging a delay in window proxy clearing.

### [CVE-2015-6770](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2015-6770)

- The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-6768.

### [CVE-2015-6771](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2015-6771.md)

- js/array.js in Google V8, as used in Google Chrome before 47.0.2526.73, improperly implements certain map and filter operations for arrays, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via crafted JavaScript code.

### [CVE-2015-7450](https://cxsecurity.com/issue/WLB-2017030142)

- Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the InvokerTransformer class in the Apache Commons Collections library.

### [CVE-2015-7501](https://github.com/joaomatosf/JavaDeserH2HC)

- Red Hat JBoss A-MQ 6.x; BPM Suite (BPMS) 6.x; BRMS 6.x and 5.x; Data Grid (JDG) 6.x; Data Virtualization (JDV) 6.x and 5.x; Enterprise Application Platform 6.x, 5.x, and 4.3.x; Fuse 6.x; Fuse Service Works (FSW) 6.x; Operations Network (JBoss ON) 3.x; Portal 6.x; SOA Platform (SOA-P) 5.x; Web Server (JWS) 3.x; Red Hat OpenShift/xPAAS 3.x; and Red Hat Subscription Asset Manager 1.3 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

### [CVE-2015-7545](https://hackmd.io/s/SkKL68GIe#🍊-web-300-git)

- The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arbitrary code via a URL in a (a) .gitmodules file or (b) unknown other sources in a submodule.

### [CVE-2015-8584](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2015-8548.md)

- JSON, OOB.

### [CVE-2016-0040](https://github.com/de7ec7ed/CVE-2016-0040)

- The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

### [CVE-2016-0450](https://redr2e.com/cve-to-poc-cve-2016-0450/)

- Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect availability via unknown vectors.

### [CVE-2016-0451](https://redr2e.com/cve-to-poc-cve-2016-0451/)

- Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0452.

### [CVE-2016-0728](https://github.com/geekben/cve-collections/blob/master/cve20160728poc.c)

- The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.

### [CVE-2016-0788](https://blog.csdn.net/u011721501/article/details/78548997)

- The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.

### [CVE-2016-0792](https://github.com/jpiechowka/jenkins-cve-2016-0792)

- Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.

### [CVE-2016-0856](https://github.com/thezdi/PoC/tree/master/CVE-2016-0856)

- Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.

### [CVE-2016-1631](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-1631)

- The PPB_Flash_MessageLoop_Impl::InternalRun function in content/renderer/pepper/ppb_flash_message_loop_impl.cc in the Pepper plugin in Google Chrome before 49.0.2623.75 mishandles nested message loops, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

### [CVE-2016-1646](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2016-1646.md)

- The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.

### [CVE-2016-1653](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2016-1653.md)

- The LoadBuffer implementation in Google V8, as used in Google Chrome before 50.0.2661.75, mishandles data types, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers an out-of-bounds write operation, related to compiler/pipeline.cc and compiler/simplified-lowering.cc.

### [CVE-2016-1665](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2016-1665.md)

- The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information via crafted JavaScript code.

### [CVE-2016-1667](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-1667)

- The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

### [CVE-2016-1668](https://github.com/Metnew/uxss-db/blob/master/chrome/CVE-2016-1668)

- The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

### [CVE-2016-1669](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2016-1669.md)

- The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.

### [CVE-2016-1672](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-1672)

- The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings-interception attacks and bypass the Same Origin Policy via unspecified vectors.

### [CVE-2016-1673](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-1673)

- Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

### [CVE-2016-1674](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-1674)

- The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

### [CVE-2016-1675](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-1675)

- Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.

### [CVE-2016-1676](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-1676)

- extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

### [CVE-2016-1677](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2016-1677.md)

- uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion".

### [CVE-2016-1688](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2016-1688.md)

- The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted JavaScript code.

### [CVE-2016-1697](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-1697)

- The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not prevent frame navigations during DocumentLoader detach operations, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

### [CVE-2016-1710](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-1710)

- The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not prevent window creation by a deferred frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

### [CVE-2016-1711](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-1711)

- WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach operation on a DocumentLoader object, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

### [CVE-2016-1779](https://github.com/Metnew/uxss-db/tree/master/webkit/CVE-2016-1779)

- WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a crafted geolocation request.

### [CVE-2016-1857](https://github.com/tunz/js-vuln-db/blob/master/jsc/CVE-2016-1857.md)

- WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1856.

### [CVE-2016-1910](https://github.com/vah13/SAP_exploit)

- The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.

### [CVE-2016-2384](https://github.com/xairy/kernel-exploits/tree/master/CVE-2016-2384)

- Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an invalid USB descriptor.

### [CVE-2016-2386](https://github.com/vah13/SAP_exploit)

- SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

### [CVE-2016-2388](https://github.com/vah13/SAP_exploit)

- The Universal Worklist Configuration in SAP NetWeaver 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

### [CVE-2016-3087](https://github.com/nixawk/labs/tree/master/CVE-2016-3087)

- Apache Struts 2.3.20.x before 2.3.20.3, 2.3.24.x before 2.3.24.3, and 2.3.28.x before 2.3.28.1, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.

### [CVE-2016-3088](https://github.com/coffeehb/Some-PoC-oR-ExP/tree/master/ActiveMQExP)

- The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

### [CVE-2016-3309](https://siberas.de/blog/2017/10/05/exploitation_case_study_wild_pool_overflow_CVE-2016-3309_reloaded.html)

- The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3308, CVE-2016-3310, and CVE-2016-3311.

### [CVE-2016-3371](https://github.com/WindowsExploits/Exploits/tree/master/CVE-2016-3371)

- The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain sensitive information via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."

### [CVE-2016-3386](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-3386.md)

- The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3389, CVE-2016-7190, and CVE-2016-7194.

### [CVE-2016-3714](https://mukarramkhalid.com/imagemagick-imagetragick-exploit/)

- The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."

### [CVE-2016-4338](https://github.com/nixawk/labs/tree/master/CVE-2016-4338)

- The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size parameter.

### [CVE-2016-4437](https://github.com/jas502n/SHIRO-550)

- Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

### [CVE-2016-4622](https://github.com/tunz/js-vuln-db/blob/master/jsc/CVE-2016-4622.md)

- WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4623, and CVE-2016-4624.

### [CVE-2016-4734](https://github.com/tunz/js-vuln-db/blob/master/jsc/CVE-2016-4734.md)

- WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4733, and CVE-2016-4735.

### [CVE-2016-4971](https://github.com/KINGSABRI/CVE-in-Ruby/tree/master/CVE-2016-4971)

- GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

### [CVE-2016-5129](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2016-5129.md)

- Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.

### [CVE-2016-5172](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2016-5172.md)

- The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code.

### [CVE-2016-5195](https://github.com/nixawk/labs/tree/master/CVE-2016-5195)

- Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

### [CVE-2016-5198](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2016-5198.md)

- V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac included incorrect optimisation assumptions, which allowed a remote attacker to perform arbitrary read/write operations, leading to code execution, via a crafted HTML page.

### [CVE-2016-5200](https://github.com/tunz/js-vuln-db/blob/master/v8/CVE-2016-5200.md)

- V8 in Google Chrome prior to 54.0.2840.98 for Mac, and 54.0.2840.99 for Windows, and 54.0.2840.100 for Linux, and 55.0.2883.84 for Android incorrectly applied type rules, which allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

### [CVE-2016-5204](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-5204)

- Leaking of an SVG shadow tree leading to corruption of the DOM tree in Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.

### [CVE-2016-5207](https://github.com/Metnew/uxss-db/tree/master/chrome/CVE-2016-5207)

- In Blink in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android, corruption of the DOM tree could occur during the removal of a full screen element, which allowed a remote attacker to achieve arbitrary code execution via a crafted HTML page.

### [CVE-2016-5346](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2016-5346)

- An Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when processing an accept system call by the user process on AF_MSM_IPC sockets, which could let a local malicious user obtain sensitive information (Android Bug ID A-32551280).

### [CVE-2016-5610](https://github.com/renorobert/virtualbox-nat-dhcp-bugs/tree/master/CVE-2016-5610)

- Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core.

### [CVE-2016-5611](https://github.com/renorobert/virtualbox-nat-dhcp-bugs/tree/master/CVE-2016-5611)

- Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality via vectors related to Core.

### [CVE-2016-5734](https://github.com/coffeehb/Some-PoC-oR-ExP/blob/master/PhpMyAdmin/phpmyadmin4.6.2_RCE.py)

- phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted string, as demonstrated by the table search-and-replace implementation.

### [CVE-2016-6210](https://github.com/KINGSABRI/CVE-in-Ruby/tree/master/CVE-2016-6210)

- sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.

### [CVE-2016-6277](https://github.com/nixawk/labs/tree/master/CVE-2016-6277)

- NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG before 1.0.0.28.Beta, R7300DST before 1.0.0.46.Beta, R7900 before 1.0.1.8.Beta, R8000 before 1.0.3.26.Beta, D6220, D6400, D7000, and possibly other routers allow remote attackers to execute arbitrary commands via shell metacharacters in the path info to cgi-bin/.

### [CVE-2016-6415](https://github.com/nixawk/labs/tree/master/CVE-2016-6415)

- The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

### [CVE-2016-6662](https://github.com/MaYaSeVeN/CVE-2016-6662)

- Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.

### [CVE-2016-6700](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2016-6700)

- An elevation of privilege vulnerability in libzipfile in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30916186.

### [CVE-2016-6702](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2016-6702)

- A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses libjpeg. Android ID: A-30259087.

### [CVE-2016-6762](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2016-6762)

- An elevation of privilege vulnerability in the libziparchive library could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31251826.

### [CVE-2016-6787](https://hardenedlinux.github.io/system-security/2017/10/16/Exploiting-on-CVE-2016-6787.html)

- kernel/events/core.c in the performance subsystem in the Linux kernel before 4.0 mismanages locks during certain migrations, which allows local users to gain privileges via a crafted application, aka Android internal bug 31095224.

### [CVE-2016-7124](http://0x48.pw/2016/09/13/0x22/)

- ext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that leads to a (1) __destruct call or (2) magic method call.

### [CVE-2016-7189](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7189.md)

- The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Remote Code Execution Vulnerability".

### [CVE-2016-7190](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7190.md)

- The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3386, CVE-2016-3389, and CVE-2016-7194.

### [CVE-2016-7194](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7194.md)

- The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3386, CVE-2016-3389, and CVE-2016-7190.

### [CVE-2016-7200](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7200.md)

- The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

### [CVE-2016-7201](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7201.md)

- The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

### [CVE-2016-7202](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7202.md)

- The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," as demonstrated by the Chakra JavaScript engine, a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

### [CVE-2016-7203](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7203.md)

- The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7202, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

### [CVE-2016-7240](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7240.md)

- The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7242, and CVE-2016-7243.

### [CVE-2016-7241](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7241.md)

- Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability".

### [CVE-2016-7255](https://github.com/mwrlabs/CVE-2016-7255)

- The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

### [CVE-2016-7286](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7286.md)

- The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7288, CVE-2016-7296, and CVE-2016-7297.

### [CVE-2016-7287](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7287.md)

- The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability".

### [CVE-2016-7288](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2016-7288.md)

- The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7286, CVE-2016-7296, and CVE-2016-7297.

### [CVE-2016-7547](https://gist.github.com/malerisch/b8764501d299f2ec9eb145258d404e5f)

- A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface.

### [CVE-2016-7552](https://gist.github.com/malerisch/5de8b408443ee9253b3954a62a8d97b4)

- On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can be used to bypass authentication or cause a DoS.

### [CVE-2016-8413](https://github.com/derrekr/android_security/blob/master/CVE-2016-8413/msm_infoleak_main.c)

- An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32709702. References: QC-CR#518731.

### [CVE-2016-8477](https://github.com/derrekr/android_security/blob/master/CVE-2016-8477/msm_eeprom_name_infoleak_main.c)

- An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32720522. References: QC-CR#1090007.

### [CVE-2016-8584](https://gist.github.com/malerisch/0b8ecfcb03a2c2f26e5f649cf1df8d33)

- Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.

### [CVE-2016-8585](https://gist.github.com/malerisch/91239147d4fceffa63006974889ef1af)

- admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the timezone parameter.

### [CVE-2016-8586](https://gist.github.com/malerisch/97c160aa4e8219c7c9ad25107444a280)

- detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

### [CVE-2016-8587](https://gist.github.com/malerisch/aac1ad3e6f3bfd70b35ba6538ecbff23)

- dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sensorSDK/backup_pol/.

### [CVE-2016-8588](https://gist.github.com/malerisch/93be2141dfc5709159468762937f2853)

- The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.

### [CVE-2016-8589](https://gist.github.com/malerisch/3bbb6d0b235fa5af2ba6f05826fe3846)

- log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

### [CVE-2016-8590](https://gist.github.com/malerisch/7b84a4bd6eee0a3a591677f421653a2e)

- log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

### [CVE-2016-8591](https://gist.github.com/malerisch/5dd838a723b342bb04121f29a8333e00)

- log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

### [CVE-2016-8592](https://gist.github.com/malerisch/0c78e49124561524fd59d6635007eefd)

- log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

### [CVE-2016-8593](https://gist.github.com/malerisch/c59ab650c8e226ef22cdfbfeeee6d4ec)

- log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.

### [CVE-2016-9651](https://github.com/secmob/pwnfest2016/)

- A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

### [CVE-2016-9793](https://github.com/xairy/kernel-exploits/tree/master/CVE-2016-9793)

- The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUFFORCE or (2) SO_RCVBUFFORCE option.

### [CVE-2016-10033](https://exploitbox.io/vuln/WordPress-Exploit-4-6-RCE-CODE-EXEC-CVE-2016-10033.html)

- The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

### [CVE-2016-10191](https://www.secfree.com/article-396.html)

- Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.

### [CVE-2016-10277](https://alephsecurity.com/2017/05/23/nexus6-initroot/)

- An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33840490.

### [CVE-2016-10370](https://alephsecurity.com/2017/05/11/oneplus-ota/)

- An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increases the attack surface, and allows for remote exploitation of other vulnerabilities such as CVE-2017-5948, CVE-2017-8850, and CVE-2017-8851.

### [CVE-2017-0015](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2017-0015.md)

- A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.

### [CVE-2017-0037](https://redr2e.com/cve-to-poc-cve-2017-0037/)

- Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

### [CVE-2017-0059](https://redr2e.com/cve-to-poc-cve-2017-0059/)

- Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.

### [CVE-2017-0070](CVE-2017-0070.md)

- A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.

### [CVE-2017-0071](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2017-0071.md)

- A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.

### [CVE-2017-0134](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2017-0134.md)

- A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0141, CVE-2017-0150, and CVE-2017-0151.

### [CVE-2017-0135](https://medium.com/bugbountywriteup/bypass-csp-by-abusing-xss-filter-in-edge-43e9106a9754)

- Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.

### [CVE-2017-0141](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2017-0141.md)

- A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling objects in memory in Microsoft browsers. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. This vulnerability is different from those described in CVE-2017-0010, CVE-2017-0015, CVE-2017-0032, CVE-2017-0035, CVE-2017-0067, CVE-2017-0070, CVE-2017-0071, CVE-2017-0094, CVE-2017-0131, CVE-2017-0132, CVE-2017-0133, CVE-2017-0134, CVE-2017-0136, CVE-2017-0137, CVE-2017-0138, CVE-2017-0150, and CVE-2017-0151.

### [CVE-2017-0143](MS17-010.md)

- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0144, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

### [CVE-2017-0144](MS17-010.md)

- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0145, CVE-2017-0146, and CVE-2017-0148.

### [CVE-2017-0145](MS17-010.md)

- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0146, and CVE-2017-0148.

### [CVE-2017-0146](MS17-010.md)

- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0148.

### [CVE-2017-0147](MS17-010.md)

- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted packets, aka "Windows SMB Information Disclosure Vulnerability."

### [CVE-2017-0148](MS17-010.md)

- The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.

### [CVE-2017-0199](CVE-2017-0199.md)

- Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."

### [CVE-2017-0213](https://github.com/WindowsExploits/Exploits/tree/master/CVE-2017-0213)

- Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when an attacker runs a specially crafted application, aka "Windows COM Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-0214.

### [CVE-2017-0234](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2017-0234.md)

- A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0235, CVE-2017-0236, and CVE-2017-0238.

### [CVE-2017-0236](https://github.com/tunz/js-vuln-db/blob/master/chakra/CVE-2017-0236.md)

- A remote code execution vulnerability exists in Microsoft Edge in the way that the Chakra JavaScript engine renders when handling objects in memory, aka "Scripting Engine Memory Corruption Vulnerability." This CVE ID is unique from CVE-2017-0224, CVE-2017-0228, CVE-2017-0229, CVE-2017-0230, CVE-2017-0234, CVE-2017-0235, and CVE-2017-0238.

### [CVE-2017-0263](https://www.exploit-db.com/exploits/44478/)

- The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

### [CVE-2017-0283](https://0patch.blogspot.tw/2017/07/0patching-quick-brown-fox-of-cve-2017.html)

- Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, Windows Server 2016, Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office Word Viewer, Microsoft Lync 2013 SP1, Skype for Business 2016, Microsoft Silverlight 5 Developer Runtime when installed on Microsoft Windows, and Microsoft Silverlight 5 when installed on Microsoft Windows allows a remote code execution vulnerability due to the way it handles objects in memory, aka "Windows Uniscribe Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8528.

### [CVE-2017-0290](CVE-2017-0290.md)

- NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within any file scanned by this engine.

### [CVE-2017-0392](https://github.com/derrekr/android_security/blob/master/CVE-2017-0392)

- A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1. Android ID: A-32577290.

### [CVE-2017-0474](https://github.com/V-E-O/PoC/tree/master/CVE-2017-0474)

- A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-32589224.

### [CVE-2017-0475](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0475)

- An elevation of privilege vulnerability in the recovery verifier could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-31914369.

### [CVE-2017-0497](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0497)

- A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as Moderate because it requires an uncommon device configuration. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33300701.

### [CVE-2017-0521](https://github.com/derrekr/android_security/tree/master/CVE-2017-0521)

- An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32919951. References: QC-CR#1097709.

### [CVE-2017-0531](https://github.com/derrekr/android_security/blob/master/CVE-2017-0531/msm_lsm_client_lab_main.c)

- An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32877245. References: QC-CR#1087469.

### [CVE-2017-0541](https://github.com/JiounDai/CVE-2017-0541)

- A remote code execution vulnerability in sonivox in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution within the context of the Mediaserver process. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1. Android ID: A-34031018.

### [CVE-2017-0548](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0548)

- A remote denial of service vulnerability in libskia could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 7.0, 7.1.1. Android ID: A-33251605.

### [CVE-2017-0576](https://github.com/derrekr/android_security/blob/master/CVE-2017-0576/qcom_qcedev_byteoffset_overflow.c)

- An elevation of privilege vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33544431. References: QC-CR#1103089.

### [CVE-2017-0641](https://github.com/V-E-O/PoC/tree/master/CVE-2017-0641)

- A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34360591.

### [CVE-2017-0678](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0678)

- A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36576151.

### [CVE-2017-0714](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0714)

- A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492637.

### [CVE-2017-0718](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0718)

- A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273547.

### [CVE-2017-0719](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0719)

- A remote code execution vulnerability in the Android media framework (mpeg2 decoder). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37273673.

### [CVE-2017-0720](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0720)

- A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37430213.

### [CVE-2017-0722](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0722)

- A remote code execution vulnerability in the Android media framework (h263 decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37660827.

### [CVE-2017-0745](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0745)

- A remote code execution vulnerability in the Android media framework (avc decoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37079296.

### [CVE-2017-0758](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0758)

- A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36492741.

### [CVE-2017-0760](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0760)

- A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237396.

### [CVE-2017-0761](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0761)

- A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38448381.

### [CVE-2017-0764](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0764)

- A remote code execution vulnerability in the Android media framework (libvorbis). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62872015.

### [CVE-2017-0776](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0776)

- A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38496660.

### [CVE-2017-0777](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0777)

- A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-38342499.

### [CVE-2017-0778](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0778)

- A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-62133227.

### [CVE-2017-0781](CVE-2017-0781.md)

- A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146105.

### [CVE-2017-0785](https://github.com/ojasookert/CVE-2017-0785)

- A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.

### [CVE-2017-0813](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0813)

- A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-36531046.

### [CVE-2017-0814](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0814)

- An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62800140.

### [CVE-2017-0820](https://github.com/ele7enxxh/poc-exp/tree/master/CVE-2017-0820)

- A vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62187433.

### [CVE-2017-1082](Stack-Clash.md)

- In FreeBSD 11.x before 11.1-RELEASE and 10.x before 10.4-RELEASE, the qsort algorithm has a deterministic recursion pattern. Feeding a pathological input to the algorithm can lead to excessive stack usage and potential overflow. Applications that use qsort to handle large data set may crash if the input follows the pathological pattern.

### [CVE-2017-1083](Stack-Clash.md)

- In FreeBSD before 11.2-RELEASE, a stack guard-page is available but is disabled by default. This results in the possibility a poorly written process could be cause a stack overflow.

### [CVE-2017-1084](Stack-Clash.md)

- In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections afforded by the guard-page. This results in the possibility a poorly written process could be cause a stack overflow.

### [CVE-2017-1085](Stack-Clash.md)

- In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only memory region below the stack into a read-write region. A specially crafted executable could be exploited to execute arbitrary code in the user context.

### [CVE-2017-2363](https://github.com/Metnew/uxss-db/tree/master/webkit/CVE-2017-2363)

- An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS before 10.1.1 is affected. w