JoeV
33 exploits
Active since Oct 2012
Firefox < 28.0 - Remote Code Execution via Web IDL Fragment
CVSS 9.8
Firefox 17.0.1 Flash Privileged Code Injection
Firefox toString console.time Privileged Javascript Injection
Android 3.0-4.1.x - Remote Code Execution via WebView.addJavascriptInterface
Ruby 1.8 1.9-1.9.3-p484 2.0-2.0.0-p353 2.1-2.1.0 preview2 - Heap-based Buffer Overflow via String to Float Conversion
Nodejs - Improper Input Validation
Android Browser RCE Through Google Play Store XFO
Arris / Motorola Surfboard SBG6580 Web Interface Takeover
Ruby on Rails 3.x < 3.2.16 and 4.x < 4.0.2 - Denial of Service via Invalid MIME Type Header
Adobe Reader Mobile < 11.2 - Remote Code Execution via JavaScript in PDF
Android API < 16.0 - Remote Code Execution via WebView.addJavascriptInterface
Android Browser RCE Through Google Play Store XFO
iPhone OS < 8.3 and Safari < 6.2.5 - Same Origin Policy Bypass via History Implementation
Adobe Flash Player <14.0.0.145 - CSRF
Internet Explorer 9-11 - Universal Cross-Site Scripting via IFRAME Redirect and WindowProxy Eval
Apple iOS < 8.3 and Safari < 6.2.5 - Remote Resource Access via FTP URL Userinfo Field
Android Browser RCE Through Google Play Store XFO
nodeca/js-yaml < 2.0.5 - Remote Code Execution via Unsafe YAML Tag Parsing
Firefox < 28.0 - Remote Code Execution via Web IDL Fragment
CVSS 9.8
Firefox toString console.time Privileged Javascript Injection
Firefox PDF.js Privileged Javascript Injection
Firefox 5.0 - 15.0.1 __exposedProps__ XCS Code Execution
Firefox 17.0.1 Flash Privileged Code Injection
Firefox PDF.js Privileged Javascript Injection
Cisco Linksys WRT110 Firmware - Cross-Site Request Forgery
CVSS 8.8