sin99xx.com — /proc/self/maps pc 0x0000000000400000
Vulnerability research. Bug bounty. Tooling.
addr +0 +1 +2 +3 +4 +5 +6 +7 ascii 0000 77 61 72 69 73 6a 65 65 |warisjee| 0008 74 00 00 00 00 00 00 00 |t.......| 0010 73 69 6e 39 39 78 78 00 |sin99xx.| 0018 ff ff ff ff ff ff ff ff |........|
| Target | ID | Finding |
|---|---|---|
| Joomla com_modules | CVE-2026-48956 access control |
An improper access check in the core lets unprivileged users enumerate a list of modules from the frontend. Incorrect access control in com_modules. Advisory |
| Exim | CVE-2026-48840 pre-auth leak |
Uninitialised stack memory leaks through the PROXY-protocol parser, no auth required. An ASLR defeat against internet-facing mail servers. Advisory |
| QEMU | CVE-2026-48004 heap UAF |
Freed object reachable from guest-controlled state in device emulation. The front half of a guest-to-host escape on multi-tenant cloud. 5a8da7e |
| Gemini iOS | CVE-2025-5009 info disclosure |
Share a snippet, leak the conversation: the public link carried the entire history, not the excerpt. NVD |
| Project | Change | Fix |
|---|---|---|
| Go Google | CL 789862 crypto/tls |
Pre-1.3 TLS server handshakes set ConnectionState.LocalCertificate on resumed connections, reporting a chain that was never presented to the peer. Moved population to where the Certificate message is actually written. CL |
| XNNPACK Google · LiteRT | #10464 heap OOB write |
Missing bounds checks in the LiteRT tensor builder let a crafted model drive a heap out-of-bounds write. PR |
| XNNPACK Google | #10463 OOB read |
Out-of-bounds read in the qb4w transposed-weight packer. PR |
| XNNPACK Google | #10373 heap OOB write |
CONCATENATE never checked that inputs matched on non-axis dimensions, so a sibling with a larger trailing product overran the output buffer — attacker-controlled length and content, reachable from an untrusted model through the default float delegate. PR |
1win / DoorDash / Monero / Whoop / Eightfold / private programs