sophoslabs

2 exploits Active since Feb 2019
CVE-2018-18500 NOMISEC CRITICAL WORKING POC
Firefox < 65.0 - Use-After-Free in HTML5 Stream Parser
A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.
61 stars
CVSS 9.8
CVE-2019-0888 NOMISEC HIGH WRITEUP
Microsoft Windows ADO - ActiveX Data Objects Remote Code Execution
A remote code execution vulnerability exists in the way that ActiveX Data Objects (ADO) handle objects in memory. An attacker who successfully exploited the vulnerability could execute arbitrary code with the victim user’s privileges. An attacker could craft a website that exploits the vulnerability and then convince a victim user to visit the website. The security update addresses the vulnerability by modifying how ActiveX Data Objects handle objects in memory.
40 stars
CVSS 8.8