Google Project Zero
24 exploits
Active since Jun 2015
Safari < 15.3 - Use-After-Free via Malicious Web Content
Lenovo Diagnostics < 5.26.0 and Lenovo Vantage < 4.7.1.4 - Authenticated Arbitrary File Write via Hardware Scan
Android Binder Use-After-Free Exploit
CVSS 7.8
JerryScript 2.2.0 - Control Flow Hijacking via Register Manipulation
CVSS 7.5
cgit < 1.2.1 - Path Traversal via git/objects/?path=../ Request
CVSS 7.5
Windows Kernel - Local Privilege Escalation via Registry API Call
CVSS 5.0
NVIDIA GPU Driver R340 < 342.00 & R375 < 375.63 - DoS or Privilege Escalation via UVMLiteController IOCTL
CVSS 7.8
Windows 10 and Windows Server 2016 - Privilege Escalation via VHD Driver
CVSS 6.1
Microsoft Windows 8.1/10, Server 2012, RT 8.1 - Local Privilege Escalation via Registry API
CVSS 5.5
Microsoft Windows and Office - ASLR Bypass via TrueType Font Parsing
CVSS 5.5
NVIDIA Windows GPU Display Driver R340 <342.00 and R375 <375.63 - DoS
CVSS 7.8
NVIDIA GPU Driver R340 < 342.00 & R375 < 375.63 - DoS or Privilege Escalation via Unvalidated Array Index
CVSS 7.8
Oracle VM VirtualBox <5.0.38-5.1.20 - RCE
CVSS 8.5
CUPS < 2.0.3 - Remote Code Execution via IPP Job Request
Adobe Flash Player <18.0.0.268, 19.x, 20.x - RCE
Adobe Flash Player <= 25.0.0.127 - Memory Corruption via Shape Outline Parsing
CVSS 7.8
Adobe Flash Player < 26.0.0.151 - Memory Corruption in Text Handling
CVSS 9.8
Adobe Flash Player < 24.0.0.194 - Remote Code Execution via FLV Codec Heap Overflow
CVSS 8.8
Adobe Flash Player < 24.0.0.186 - Use-After-Free in ActionScript MovieClip
CVSS 8.8
Adobe Flash Player <21.0.0.213 - Unspecified Vuln
CVSS 7.5
OpenSSH <7.4 - Privilege Escalation
CVSS 7.0
Oracle VM VirtualBox - Cooperating VMs can Escape from Shared Folder
Debian/Ubuntu ntfs-3g Local Privilege Escalation
CVSS 7.8
Google Android - 'rkp_set_init_page_ro' RKP Memory Corruption