Jann Horn
81 exploits
Active since May 2015
Android Binder Use-After-Free Exploit
CVSS 7.8
VMware Workstation Pro/Player - Privilege Escalation
CVSS 7.8
Linux Polkit pkexec helper PTRACE_TRACEME local root exploit
CVSS 7.8
Linux Nested User Namespace idmap Limit Local Privilege Escalation
CVSS 7.0
Watch Queue Out of Bounds Write
CVSS 7.8
Linux BPF Sign Extension Local Privilege Escalation
CVSS 7.8
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
CVSS 5.5
Google Chrome - 'layout' Out-of-Bounds Read
OpenSSH < 6.6 SFTP (x64) - Command Execution
Linux Polkit pkexec helper PTRACE_TRACEME local root exploit
CVSS 7.8
Xen 64bit PV Guest - pagetable use-after-type-change Breakout
VMware Workstation - ALSA Config File Local Privilege Escalation (Metasploit)
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
CVSS 5.5
Linux Polkit pkexec helper PTRACE_TRACEME local root exploit
CVSS 7.8
Linux Nested User Namespace idmap Limit Local Privilege Escalation
CVSS 7.0
Linux Nested User Namespace idmap Limit Local Privilege Escalation
CVSS 7.0
Linux Nested User Namespace idmap Limit Local Privilege Escalation
CVSS 7.0
Linux Nested User Namespace idmap Limit Local Privilege Escalation
CVSS 7.0
Linux Polkit pkexec helper PTRACE_TRACEME local root exploit
CVSS 7.8
Linux Nested User Namespace idmap Limit Local Privilege Escalation
CVSS 7.0
Linux Nested User Namespace idmap Limit Local Privilege Escalation
CVSS 7.0
Linux BPF Sign Extension Local Privilege Escalation
CVSS 7.8
Linux < 4.16.9 / < 4.14.41 - 4-byte Infoleak via Uninitialized Struct Field in compat adjtimex Syscall
Linux - 'page->_refcount' Overflow via FUSE
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
CVSS 5.5