exploit-db-mirror/exploits
Offensive Security c35d9b35f7 DB: 2017-12-09
14 changes to exploits/shellcodes

macOS < 10.12.2 / iOS < 10.2 Kernel - ipc_port_t Reference Count Leak Due to Incorrect externalMethod Overrides Use-After-Free
macOS 10.12.1 / iOS < 10.2 - powerd Arbitrary Port Replacement
macOS 10.12.1 / iOS < 10.2 - syslogd Arbitrary Port Replacement
Apple macOS < 10.12.2 / iOS < 10.2 Kernel - ipc_port_t Reference Count Leak Due to Incorrect externalMethod Overrides Use-After-Free
Apple macOS 10.12.1 / iOS < 10.2 - powerd Arbitrary Port Replacement
Apple macOS 10.12.1 / iOS < 10.2 - syslogd Arbitrary Port Replacement
macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption
macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
macOS 10.12.1 / iOS Kernel - 'host_self_trap' Use-After-Free
Apple macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption
Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
Apple macOS 10.12.1 / iOS Kernel - 'host_self_trap' Use-After-Free
Wireshark 2.4.0 - 2.4.2 / 2.2.0 - 2.2.10 - CIP Safety Dissector Crash
Linux Kernel - DCCP Socket Use-After-Free
Wireshark 2.4.0 < 2.4.2 / 2.2.0 < 2.2.10 - CIP Safety Dissector Crash
Linux Kernel 4.10.5 / < 4.14.3 (Ubuntu) - DCCP Socket Use-After-Free

iOS 10.1.1 / macOS 10.12 16A323 XNU Kernel - set_dp_control_port Lack of Locking Use-After-Free
Apple iOS 10.1.1 / macOS 10.12 16A323 XNU Kernel - set_dp_control_port Lack of Locking Use-After-Free

macOS < 10.12.2 / iOS < 10.2 - Broken Kernel Mach Port Name uref Handling Privileged Port Name Replacement Privilege Escalation
Apple macOS < 10.12.2 / iOS < 10.2 - Broken Kernel Mach Port Name uref Handling Privileged Port Name Replacement Privilege Escalation

iOS/macOS - xpc_data Objects Sandbox Escape Privelege Escalation
Apple iOS/macOS - 'xpc_data' Objects Sandbox Escape Privilege Escalation

macOS High Sierra - Local Privilege Escalation (Metasploit)
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation (Metasploit)
Apple macOS 10.13.1 (High Sierra) - Insecure Cron System Local Privilege Escalation
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation

LabF nfsAxe FTP Client 3.7 - Buffer Overflow (DEP Bypass)
DomainSale PHP Script 1.0 - 'id' SQL Injection
Simple Chatting System 1.0.0 - Arbitrary File Upload
Website Auction Marketplace 2.0.5 - 'cat_id' SQL Injection
Realestate Crowdfunding Script 2.7.2 - 'pid' SQL Injection
FS Thumbtack Clone 1.0 - 'cat' / 'sc' SQL Injection
FS Stackoverflow Clone 1.0 - 'keywords' SQL Injection
FS Shutterstock Clone 1.0 - 'keywords' SQL Injection
FS Quibids Clone 1.0 - SQL Injection
FS Olx Clone 1.0 - 'scat' / 'pid' SQL Injection
FS Monster Clone 1.0 - 'Employer_Details.php?id' SQL Injection
2017-12-09 05:02:21 +00:00
..
aix DB: 2017-11-24 2017-11-24 20:56:23 +00:00
android DB: 2017-11-29 2017-11-29 10:22:56 +00:00
arm DB: 2017-11-24 2017-11-24 20:56:23 +00:00
ashx/webapps DB: 2017-11-24 2017-11-24 20:56:23 +00:00
asp DB: 2017-11-24 2017-11-24 20:56:23 +00:00
aspx/webapps DB: 2017-11-24 2017-11-24 20:56:23 +00:00
atheos/local DB: 2017-11-24 2017-11-24 20:56:23 +00:00
beos DB: 2017-11-24 2017-11-24 20:56:23 +00:00
bsd DB: 2017-11-24 2017-11-24 20:56:23 +00:00
bsd_x86/remote DB: 2017-11-24 2017-11-24 20:56:23 +00:00
cfm DB: 2017-11-24 2017-11-24 20:56:23 +00:00
cgi DB: 2017-12-08 2017-12-08 05:02:13 +00:00
freebsd DB: 2017-11-24 2017-11-24 20:56:23 +00:00
freebsd_x86/dos DB: 2017-11-24 2017-11-24 20:56:23 +00:00
freebsd_x86-64/dos DB: 2017-11-24 2017-11-24 20:56:23 +00:00
hardware DB: 2017-11-29 2017-11-29 10:22:56 +00:00
hp-ux DB: 2017-11-24 2017-11-24 20:56:23 +00:00
immunix/local DB: 2017-11-24 2017-11-24 20:56:23 +00:00
ios DB: 2017-11-24 2017-11-24 20:56:23 +00:00
irix DB: 2017-11-24 2017-11-24 20:56:23 +00:00
java DB: 2017-11-24 2017-11-24 20:56:23 +00:00
json/webapps DB: 2017-11-24 2017-11-24 20:56:23 +00:00
jsp DB: 2017-12-01 2017-12-01 10:57:46 +00:00
lin_x86 DB: 2017-11-24 2017-11-24 20:56:23 +00:00
lin_x86-64 DB: 2017-11-24 2017-11-24 20:56:23 +00:00
linux DB: 2017-12-08 2017-12-08 05:02:13 +00:00
linux_mips/remote DB: 2017-11-24 2017-11-24 20:56:23 +00:00
linux_sparc/remote DB: 2017-11-24 2017-11-24 20:56:23 +00:00
macos DB: 2017-12-09 2017-12-09 05:02:21 +00:00
minix/dos DB: 2017-11-24 2017-11-24 20:56:23 +00:00
multiple DB: 2017-12-08 2017-12-08 05:02:13 +00:00
netbsd_x86 DB: 2017-11-24 2017-11-24 20:56:23 +00:00
netware DB: 2017-12-01 2017-12-01 10:57:46 +00:00
nodejs/webapps DB: 2017-11-24 2017-11-24 20:56:23 +00:00
novell DB: 2017-11-24 2017-11-24 20:56:23 +00:00
openbsd DB: 2017-11-24 2017-11-24 20:56:23 +00:00
osx DB: 2017-12-01 2017-12-01 10:57:46 +00:00
osx_ppc/remote DB: 2017-11-24 2017-11-24 20:56:23 +00:00
palm_os DB: 2017-11-24 2017-11-24 20:56:23 +00:00
perl/webapps DB: 2017-11-24 2017-11-24 20:56:23 +00:00
php DB: 2017-12-09 2017-12-09 05:02:21 +00:00
plan9/local DB: 2017-11-24 2017-11-24 20:56:23 +00:00
python DB: 2017-11-24 2017-11-24 20:56:23 +00:00
qnx DB: 2017-11-24 2017-11-24 20:56:23 +00:00
ruby DB: 2017-11-24 2017-11-24 20:56:23 +00:00
sco DB: 2017-11-24 2017-11-24 20:56:23 +00:00
solaris DB: 2017-11-24 2017-11-24 20:56:23 +00:00
solaris_sparc/remote DB: 2017-11-24 2017-11-24 20:56:23 +00:00
solaris_x86/local DB: 2017-11-24 2017-11-24 20:56:23 +00:00
tru64 DB: 2017-11-24 2017-11-24 20:56:23 +00:00
ultrix DB: 2017-11-24 2017-11-24 20:56:23 +00:00
unix DB: 2017-12-08 2017-12-08 05:02:13 +00:00
unixware DB: 2017-11-24 2017-11-24 20:56:23 +00:00
win_x86 DB: 2017-12-01 2017-12-01 10:57:46 +00:00
win_x86-64 DB: 2017-11-24 2017-11-24 20:56:23 +00:00
windows DB: 2017-12-09 2017-12-09 05:02:21 +00:00
xml DB: 2017-11-24 2017-11-24 20:56:23 +00:00