"Testing can prove the presence of bugs, but not their absence."
-- Edsger W. Dijkstra
- CVE-2006-1242. Linux kernel IP ID information disclosure weakness.
- 2003-01-openssh. OpenSSH/PAM delay information disclosure vulnerability (CVE-2003-0190).
- CVE-2006-5229. OpenSSH information disclosure via timing leak.
- CVE-2022-46285. Infinite loop on unclosed comments handling XPM files in libXpm.
- CVE-2024-25110. Integer wraparound vulnerability in Azure IoT Platform Device SDK.
- CVE-2024-29195. Integer wraparound vulnerability in Azure C SDK.
- 2019-01-cde-dtprintinfo. Local privilege escalation via CDE dtprintinfo (CVE-2019-2832).
- 2019-02-solaris-xscreensaver. Local privilege escalation via xscreensaver (CVE-2019-3010).
- 2020-01-solaris-xlock. Low impact information disclosure via Solaris xlock (CVE-2020-2656).
- 2020-02-cde-dtsession. Local privilege escalation via CDE dtsession (CVE-2020-2696).
- 2020-05-cde-sdtcm_convert. Local privilege escalation via CDE sdtcm_convert (CVE-2020-2944).
- 2020-06-cde-libDtSvc. Stack-based buffer overflow in CDE libDtSvc (CVE-2020-2851).
- 2020-07-solaris-whodo-w. Heap-based buffer overflow in Solaris whodo, w commands (CVE-2020-2771).
- HNS-2022-01-dtprintinfo. Multiple vulnerabilities in Solaris dtprintinfo and libXm/libXpm (CVE-2022-46285, CVE-2023-24039, CVE-2023-24040).
- HNS-2022-02-zyxel-zysh. Multiple vulnerabilities in Zyxel zysh (CVE-2022-26531, CVE-2022-26532).
- HNS-2023-03-zephyr. Multiple vulnerabilities in Zephyr RTOS (CVE-2023-3725, CVE-2023-4257, CVE-2023-4259, CVE-2023-4260, CVE-2023-4261, CVE-2023-4262, CVE-2023-4263, CVE-2023-4264, CVE-2023-4265, CVE-2023-5139, CVE-2023-5184, CVE-2023-5753).
- HNS-2024-05-rt-thread. Multiple vulnerabilities in RT-Thread RTOS (CVE-2024-24334, CVE-2024-24335, CVE-2024-25388, CVE-2024-25389, CVE-2024-25390, CVE-2024-25391, CVE-2024-25392, CVE-2024-25393, CVE-2024-25394, CVE-2024-25395).
- HNS-2024-06-threadx. Multiple vulnerabilities in Eclipse ThreadX (CVE-2024-2212, CVE-2024-2214, CVE-2024-2452).
- HNS-2024-07-riot. Multiple vulnerabilities in RIOT OS (CVE-2024-31225, CVE-2024-32017, CVE-2024-32018).
- smbfs/umount. Buffer overflow in Illumos smbfs/umount.
- dhclient. Format string bug in ISC DHCP configuration file handling.
- coturn. Security issues in the Coturn TURN server.
- FreeRTOS-Plus-TCP. Security issues in FreeRTOS (uncredited).
- lwIP/httpclient. Integer wraparound and heap buffer overflow in lwIP (uncredited).
- lwIP/makefsdata. Integer underflow and static buffer overflow (uncredited).
- HNS-2023-04-tinydir. Buffer overflow vulnerabilities with long path names in TinyDir (CVE-2023-49287).