Shlomi Oberman

2 exploits Active since Jun 2020
CVE-2020-11896 NOMISEC CRITICAL WORKING POC
Treck TCP/IP < 6.0.1.66 - Remote Code Execution via IPv4 Tunneling
The Treck TCP/IP stack before 6.0.1.66 allows Remote Code Execution, related to IPv4 tunneling.
8 stars
CVSS 10.0
CVE-2020-7461 NOMISEC HIGH WORKING POC
FreeBSD Heap Overflow via DHCP Option 119 Handling
In FreeBSD 12.1-STABLE before r365010, 11.4-STABLE before r365011, 12.1-RELEASE before p9, 11.4-RELEASE before p3, and 11.3-RELEASE before p13, dhclient(8) fails to handle certain malformed input related to handling of DHCP option 119 resulting a heap overflow. The heap overflow could in principle be exploited to achieve remote code execution. The affected process runs with reduced privileges in a Capsicum sandbox, limiting the immediate impact of an exploit.
1 stars
CVSS 7.3