exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New
Showing 76 - 100 of 337 RSS Feed

Files from mjurczyk

Email addressmjurczyk at google.com
First Active2015-08-19
Last Active2023-09-29
Microsoft DirectWrite / AFDKO OpenType Stack Corruption
Posted Jul 12, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a stack corruption vulnerability in OpenType font handling while processing CFF blend DICT operator.

tags | exploit
advisories | CVE-2019-1123
SHA-256 | 4fcf434e418ec4b78b4c2d63832210327781ed08e528c125015656abfd99f10d
Microsoft DirectWrite / AFDKO OpenType Out-Of-Bounds Read / Write
Posted Jul 11, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a heap-baeed out-of-bounds read/write vulnerability in OpenType font handling due to empty ROS strings.

tags | exploit
advisories | CVE-2019-1124
SHA-256 | 776e4d5cb07c5edc399a8c06b2c8fe7a2cb08c78b74a62a84252a02d5708c119
Microsoft DirectWrite / AFDKO dnaGrow Insufficient Integer Overflow Check
Posted Jul 11, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from having an insufficient integer overflow check in dnaGrow.

tags | advisory, overflow
SHA-256 | 51c785aaeac307b6f004977e9dda66854c854edace9664c3df8a5c5e0aa2a972
Microsoft DirectWrite / AFDKO OpenType Out-Of-Bounds Read
Posted Jul 11, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from an out-of-bounds read vulnerability in OpenType font handling due to undefined FontName index.

tags | exploit
SHA-256 | e3e7b0305f8432ddd997bdec2f0d5cacd36f1c9f6a99150af8de8f307cea29f4
Microsoft DirectWrite / AFDKO OpenType Post Table Bugs
Posted Jul 11, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from multiple bugs in OpenType font handling related to the "post" table.

tags | exploit
SHA-256 | 6354ddf2c2a84f87b95ff67efeff3f139b9cc0c1d499d184289892fb322d4120
Microsoft DirectWrite / AFDKO OpenType NULL Pointer Dereference
Posted Jul 11, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a NULL pointer dereferences vulnerability in OpenType font handling while accessing empty dynarrays.

tags | exploit
SHA-256 | 4ec1a9e1b55b066d5ae525c5cd2a521b59c106b8837891bac4d6224817cffbca
Microsoft DirectWrite / AFDKO OpenType Read Of Uninitialized Memory
Posted Jul 11, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from allowing a read of uninitialized BuildCharArray memory in OpenType font handling.

tags | advisory
SHA-256 | 6bd13a875e56d5d9ee6b4e88a96b9bfc00297a1df5f42b95b9960166caf6299b
Microsoft DirectWrite / AFDKO OpenType readEncoding Buffer Overflow
Posted Jul 11, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a heap-based buffer overflow vulnerability in OpenType font handling in readEncoding.

tags | exploit, overflow
SHA-256 | 18da01543383d44711f3953c7c081e706b908f64132617f3f3e209a9d3f3d24b
Microsoft DirectWrite / AFDKO OpenType readCharset Buffer Overflow
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a heap-based buffer overflow vulnerability in OpenType font handling in readCharset.

tags | exploit, overflow
advisories | CVE-2019-1128
SHA-256 | a9d786e193b92f19f2203e1c4c4a184d6088e7ac59d89e26d75a0de326d918b1
Microsoft DirectWrite / AFDKO OpenType Out-Of-Bounds Read / Write
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a heap-based out-of-bounds read/write vulnerability in OpenType font handling due to unbounded iFD.

tags | exploit
advisories | CVE-2019-1121
SHA-256 | e74d7eca66fac35dabca0f0b4ab4a2d55f72889c670a0b7f8bf2ff79eed66baa
Microsoft DirectWrite / AFDKO Uninitialized Memory Use
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from an issue where it makes use of uninitialized memory while freeing resources in var_loadavar.

tags | exploit
SHA-256 | 5a7a6f30beafa844977ce32830f5b3436dfda461f17af14e426ffbfca386c979
Microsoft DirectWrite / AFDKO do_set_weight_vector_cube Buffer Overflow
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a stack-based buffer overflow vulnerability in do_set_weight_vector_cube for large nAxes.

tags | exploit, overflow
SHA-256 | 87a891d20df4c6c1cf489ae7aea464da6ea68dc962c56e93de1a2aaa3bed36e3
Microsoft DirectWrite / AFDKO OpenType Stack Corruption Due To Negative nAxes
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a stack corruption vulnerability in OpenType font handling due to negative nAxes.

tags | exploit
advisories | CVE-2019-1127
SHA-256 | 0b18f867565f67bca980d7fc0ababb77f4d56781f8ff941b85c87c7f67cac560
Microsoft DirectWrite / AFDKO OpenType Stack Corruption Due To Negative cubeStackDepth
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a stack corruption vulnerability in OpenType font handling due to negative cubeStackDepth.

tags | exploit
advisories | CVE-2019-1118
SHA-256 | 151943d6fedcadaa27f44c6659dd65a5bae0b90b376bb58c73d25d660f26876e
Microsoft DirectWrite / AFDKO OpenType Stack Corruption Due To Out-Of-Bounds cubeStackDepth
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a stack corruption vulnerability in OpenType font handling due to out-of-bounds cubeStackDepth.

tags | exploit
advisories | CVE-2019-1117
SHA-256 | 433ecac33a84ccd0549ea6aa46ccdf5bf0f3c6881fa170ad87339fd144605d9b
Microsoft DirectWrite / AFDKO readTTCDirectory Integer Overflow
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a heap-based buffer overflow vulnerability due to integer overflow in readTTCDirectory.

tags | exploit, overflow
SHA-256 | 7e129e9a0001c1d4d6ccb6395d7cf5e1b831314a52c02a49a35d93d927795db4
Microsoft DirectWrite / AFDKO OpenType readStrings Buffer Overflow
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a heap-based buffer overflow vulnerability in OpenType font handling in readStrings.

tags | exploit, overflow
advisories | CVE-2019-1122
SHA-256 | cf4bfe42dda84668b42617981dc6722b34f026c966dfa5c20e002f103ed59da1
Microsoft DirectWrite / AFDKO OpenType blendArray Stack Corruption
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a stack corruption vulnerability in OpenType font handling due to incorrect handling of blendArray.

tags | exploit
advisories | CVE-2019-1119
SHA-256 | 04a1b32bb8fb2c91b1b0b567ecd691256c5c85bedc90cda40c7de13c5e385668
Microsoft DirectWrite / AFDKO OpenType Stack Underflow
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from an interpreter stack underflow in OpenType font handling due to missing CHKUFLOW.

tags | exploit
SHA-256 | adff25b8214c8313e2c7f6d804197ec798b268aef4bbae69ece436523ed95da1
Microsoft DirectWrite / AFDKO OpenType readFDSelect Buffer Overflow
Posted Jul 10, 2019
Authored by Google Security Research, mjurczyk

Microsoft DirectWrite / AFDKO suffers from a heap-based buffer overflow vulnerability in OpenType font handling in readFDSelect.

tags | exploit, overflow
advisories | CVE-2019-1120
SHA-256 | 276645f96ebe21844771be3cbdc0c6d384ebe2a8d5bdb89b4c51e20d0c5fc375
Microsoft Font Subsetting DLL MergeFonts Out Of Bounds Read
Posted Jul 9, 2019
Authored by Google Security Research, mjurczyk

An issue has been discovered where the Microsoft Font Subsetting DLL (fontsub.dll) suffers from a heap-based out-of-bounds read vulnerability in MergeFonts.

tags | exploit
SHA-256 | 59bdcf0c53bae14944835fcc600e7d18a2f131991f8e5f86054a589716d13344
Oracle Java Runtime Environment GlyphIterator::setCurrGlyphID Heap Corruption
Posted Apr 17, 2019
Authored by Google Security Research, mjurczyk

A heap corruption was observed in Oracle Java Runtime Environment version 8u202 (latest at the time of this writing) while fuzz-testing the processing of TrueType fonts.

tags | exploit, java
advisories | CVE-2019-2698
SHA-256 | 3c3d35dfc5426eaa61ae91b3e754f6e09c909445eb2f9484504d724fdedd1db5
Oracle Java Runtime Environment sc_FindExtrema4 Heap Corruption
Posted Apr 17, 2019
Authored by Google Security Research, mjurczyk

A heap corruption was observed in Oracle Java Runtime Environment version 8u202 (latest at the time of this writing) while fuzz-testing the processing of TrueType, implemented in a proprietary t2k library.

tags | exploit, java
advisories | CVE-2019-2697
SHA-256 | cc1fdb072ca05f2a5b04c3cb9301fdc0fce66245b901c57e61aba6f76f5054ec
tcpdump Out-Of-Bounds Read
Posted Feb 27, 2019
Authored by Google Security Research, mjurczyk

tcpdump was found to suffer from multiple out-of-bounds read vulnerabilities.

tags | exploit, vulnerability
SHA-256 | cea131972888984634d05f66fcb925a4eaa31822c00269467fbc5939cb230885
Oracle Java Runtime Environment TTF Font Heap Out-Of-Bounds Read
Posted Feb 18, 2019
Authored by Google Security Research, mjurczyk

A heap-based out-of-bounds read was observed in Oracle Java Runtime Environment version 8u202 while fuzz-testing the processing of TrueType fonts rendering in AlternateSubstitutionSubtable::process.

tags | exploit, java
SHA-256 | 711068adf214eb589d571d06d8497f1cfb5051a638536518b30c31c08d5d0231
Page 4 of 14
Back23456Next

File Archive:

September 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    2 Files
  • 2
    Sep 2nd
    21 Files
  • 3
    Sep 3rd
    0 Files
  • 4
    Sep 4th
    17 Files
  • 5
    Sep 5th
    34 Files
  • 6
    Sep 6th
    29 Files
  • 7
    Sep 7th
    11 Files
  • 8
    Sep 8th
    25 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    26 Files
  • 12
    Sep 12th
    23 Files
  • 13
    Sep 13th
    17 Files
  • 14
    Sep 14th
    22 Files
  • 15
    Sep 15th
    16 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    19 Files
  • 19
    Sep 19th
    60 Files
  • 20
    Sep 20th
    23 Files
  • 21
    Sep 21st
    15 Files
  • 22
    Sep 22nd
    8 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    17 Files
  • 26
    Sep 26th
    3 Files
  • 27
    Sep 27th
    13 Files
  • 28
    Sep 28th
    5 Files
  • 29
    Sep 29th
    12 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close