Firefox version 44.0.2 ASM.JS JIT-Spray remote code execution exploit.
f719f8ea47c6ce0616cd666a0782ec9a6974470b392ebbc5a822945312f3a613
Firefox version 46.0.1 ASM.JS JIT-Spray remote code execution exploit.
e92d0ee402f3ff8163f3651e059e3697b41c5eff957b0ff73a04eec19a6dfa27
Firefox version 50.0.1 full ASLR and DEP bypass exploit using ASM.JS JIT-spray.
86cecd285d657c050c53a7f7a6a47081e1bc4db32994a106122cf7a3a0d39213
This Metasploit module exploits a buffer overflow in the VideoPlayer.ocx ActiveX installed with the X360 Software. By setting an overly long value to 'ConvertFile()',an attacker can overrun a .data buffer to bypass ASLR/DEP and finally execute arbitrary code.
4db85b31081245af192050fe8238d0162d228493f03b7b13875c3b7820cfcf47
This Metasploit module exploits a flaw in the Web Start component of the Sun Java Runtime Environment. Parameters intial-heap-size and max-heap-size in a JNLP file can contain a double quote which is not properly sanitized when creating the command line for javaw.exe. This allows the injection of the -XXaltjvm option to load a jvm.dll from a remote UNC path into the java process. Thus an attacker can execute arbitrary code in the context of a browser user. This flaw was fixed in Oct. 2012 and affects JRE <= 1.6.35 and <= 1.7.07. In order for this module to work, it must be ran as root on a server that does not serve SMB. Additionally, the target host must have the WebClient service (WebDAV Mini-Redirector) enabled. Alternatively an UNC path containing a jvm.dll can be specified with an own SMB server.
03e81d85cf7b77c63f98b9875e24d7c92e3dd03261f33f78773cc25fedd945f5
This Metasploit module exploits a flaw in the Web Start component of the Sun Java Runtime Environment. Parameters intial-heap-size and max-heap-size in a JNLP file can contain a double quote which is not properly sanitized when creating the command line for javaw.exe. This allows the injection of the -XXaltjvm option to load a jvm.dll from a remote UNC path into the java process. Thus an attacker can execute arbitrary code in the context of a browser user. This flaw was fixed in Oct. 2012 and affects JRE <= 1.6.35 and <= 1.7.07. In order for this module to work, it must be ran as root on a server that does not serve SMB. Additionally, the target host must have the WebClient service (WebDAV Mini-Redirector) enabled. Alternatively an UNC path containing a jvm.dll can be specified with an own SMB server.
7c4106b8276c9c6b588b2cdcba693eefaab7d0e2605a82a0728828840ed79442
This Metasploit module exploits the default security setting in the Dolphin3D web browser. The default security setting ("cautious") allows arbitrary ActiveX Controls, thus remote command execution.
356432cc5a9b8dbe3b7cd92ed21f0924cd81ae63cc754755cb391a791fa19e5b
This Metasploit module exploits a stack buffer overflow in iTunes 10.4.0.80 to 10.6.1.7. When opening an extended .m3u file containing an "#EXTINF:" tag description, iTunes will copy the content after "#EXTINF:" without appropriate checking from a heap buffer to a stack buffer and write beyond the stack buffers boundary. This allows arbitrary code execution. The Windows XP target has to have QuickTime 7.7.2 installed for this module to work. It uses a ROP chain from a non safeSEH enabled DLL to bypass DEP and safeSEH. The stack cookie check is bypassed by triggering a SEH exception.
9ae85a7f65f089284af05d455b2e76edf1411cf55e1aa37c56ec9d74328747ac
This Metasploit module exploits a stack based buffer overflow in CCMPlayer 1.5. Opening a m3u playlist with a long track name, a SEH exception record can be overwritten with parts of the controllable buffer. SEH execution is triggered after an invalid read of an injectable address, thus allowing arbitrary code execution. This Metasploit module works on multiple Windows platforms including: Windows XP SP3, Windows Vista, and Windows 7.
b1838839c525c11d9b53cae384041c70a3a02194b24bf115638e1db8ac88a5f5
This Metasploit module exploits a stack based buffer overflow in CCMPlayer 1.5. Opening a m3u playlist with a long track name, a SEH exception record can be overwritten with parts of the controllable buffer. SEH execution is triggered after an invalid read of an injectable address, thus allowing arbitrary code execution.
62edddea0f0519c92d9a92f2e69fc9d8e1666dd6111763683d4173038b2a9bca
This Metasploit module exploits an use after free vulnerability in Mozilla Firefox 3.6.16. An OBJECT Element mChannel can be freed via the OnChannelRedirect method of the nsIChannelEventSink Interface. mChannel becomes a dangling pointer and can be reused when setting the OBJECTs data attribute. This Metasploit module uses heapspray with a minimal ROP chain to bypass DEP on Windows XP SP3.
5a6e9352732f91f5a6195ee7559b47f8ad02806dc4da4347ae745625e1ce1deb
This Metasploit module exploits an use after free vulnerability in Mozilla Firefox 3.6.16. An OBJECT Element mChannel can be freed via the OnChannelRedirect method of the nsIChannelEventSink Interface. mChannel becomes a dangling pointer and can be reused when setting the OBJECTs data attribute. This Metasploit module uses heapspray with a minimal ROP chain to bypass DEP on Windows XP SP3.
ef3c210a23b0931c66277ed381e60454ce4fd75aaa512a25b6fab13362a9a96f
CORE Multimedia Suite 2011 CORE Player version 2.4 unicode SEH buffer overflow exploit that creates a malicious .m3u file.
63342c952fe021ff28c1a8ece507b7bac34b743ed8e9587016c56e0d6ba89baa
ABBS Audio Media Player buffer overflow exploit that can create malicious .m3u and .lst files.
a2f3963e4e14eed8c0968be910c6cb551aa7345751cf57b9abe7f3232f143112
Mozilla Firefox version 3.6.8 with Adobe Reader Plugin version 9.3.4.218 DLL hijacking exploit that leverages CoolType.dll.
99b1038919a894399559f28e22a581cef9029d7635eb4ceea25c27fb6843af9f
Local Glibc shared library .so exploit that leverages browser plugin functionality.
c5f4308d0b70205197c47e067b799154236efc1c9820daf5d26e2a3e7ba94ba3