<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>exploitable &#8211; RabbitZ Academy – Next Gen Cybersecurity</title>
	<atom:link href="https://rabbitzlabs.de/tag/exploitable/feed/" rel="self" type="application/rss+xml" />
	<link>https://rabbitzlabs.de</link>
	<description>Hacking, Pentesting &#38; IT-Sicherheit lernen</description>
	<lastBuildDate>Sun, 31 May 2026 09:04:18 +0000</lastBuildDate>
	<language>de</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://rabbitzlabs.de/wp-content/uploads/2026/03/cropped-ChatGPT-Image-6.-Maerz-2026-15_04_56-32x32.png</url>
	<title>exploitable &#8211; RabbitZ Academy – Next Gen Cybersecurity</title>
	<link>https://rabbitzlabs.de</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</title>
		<link>https://rabbitzlabs.de/type-confusion-in-v8-in-google-chrome-prior-to-142-0-7444-59-allowed-a-remote-attacker-to-potentially-exploit-heap-corruption-via-a-crafted-html-page-chromium-security-severity-high-3/</link>
		
		<dc:creator><![CDATA[BlackRabbitZ]]></dc:creator>
		<pubDate>Sun, 31 May 2026 09:04:18 +0000</pubDate>
				<category><![CDATA[CVE]]></category>
		<category><![CDATA[Common Vulnerabilities]]></category>
		<category><![CDATA[exploitability]]></category>
		<category><![CDATA[exploitable]]></category>
		<category><![CDATA[Exposures]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Sicherheitslücken]]></category>
		<guid isPermaLink="false">https://rabbitzlabs.de/type-confusion-in-v8-in-google-chrome-prior-to-142-0-7444-59-allowed-a-remote-attacker-to-potentially-exploit-heap-corruption-via-a-crafted-html-page-chromium-security-severity-high-3/</guid>

					<description><![CDATA[<div>Information published.</div>]]></description>
										<content:encoded><![CDATA[<div>Information published.</div>
<hr>
<p><strong>Quelle:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13230" target="_blank">Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</title>
		<link>https://rabbitzlabs.de/type-confusion-in-v8-in-google-chrome-prior-to-142-0-7444-59-allowed-a-remote-attacker-to-potentially-exploit-heap-corruption-via-a-crafted-html-page-chromium-security-severity-high/</link>
		
		<dc:creator><![CDATA[BlackRabbitZ]]></dc:creator>
		<pubDate>Sun, 31 May 2026 09:04:17 +0000</pubDate>
				<category><![CDATA[CVE]]></category>
		<category><![CDATA[Common Vulnerabilities]]></category>
		<category><![CDATA[exploitability]]></category>
		<category><![CDATA[exploitable]]></category>
		<category><![CDATA[Exposures]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Sicherheitslücken]]></category>
		<guid isPermaLink="false">https://rabbitzlabs.de/type-confusion-in-v8-in-google-chrome-prior-to-142-0-7444-59-allowed-a-remote-attacker-to-potentially-exploit-heap-corruption-via-a-crafted-html-page-chromium-security-severity-high/</guid>

					<description><![CDATA[<div>Information published.</div>]]></description>
										<content:encoded><![CDATA[<div>Information published.</div>
<hr>
<p><strong>Quelle:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13227" target="_blank">Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</title>
		<link>https://rabbitzlabs.de/type-confusion-in-v8-in-google-chrome-prior-to-142-0-7444-59-allowed-a-remote-attacker-to-potentially-exploit-heap-corruption-via-a-crafted-html-page-chromium-security-severity-high-2/</link>
		
		<dc:creator><![CDATA[BlackRabbitZ]]></dc:creator>
		<pubDate>Sun, 31 May 2026 09:04:17 +0000</pubDate>
				<category><![CDATA[CVE]]></category>
		<category><![CDATA[Common Vulnerabilities]]></category>
		<category><![CDATA[exploitability]]></category>
		<category><![CDATA[exploitable]]></category>
		<category><![CDATA[Exposures]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Sicherheitslücken]]></category>
		<guid isPermaLink="false">https://rabbitzlabs.de/type-confusion-in-v8-in-google-chrome-prior-to-142-0-7444-59-allowed-a-remote-attacker-to-potentially-exploit-heap-corruption-via-a-crafted-html-page-chromium-security-severity-high-2/</guid>

					<description><![CDATA[<div>Information published.</div>]]></description>
										<content:encoded><![CDATA[<div>Information published.</div>
<hr>
<p><strong>Quelle:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-13226" target="_blank">Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CVE-2025-15504 lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference</title>
		<link>https://rabbitzlabs.de/cve-2025-15504-lief-project-lief-elf-binary-parser-tcc-parse_binary-null-pointer-dereference/</link>
		
		<dc:creator><![CDATA[BlackRabbitZ]]></dc:creator>
		<pubDate>Sun, 31 May 2026 09:04:16 +0000</pubDate>
				<category><![CDATA[CVE]]></category>
		<category><![CDATA[Common Vulnerabilities]]></category>
		<category><![CDATA[exploitability]]></category>
		<category><![CDATA[exploitable]]></category>
		<category><![CDATA[Exposures]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Sicherheitslücken]]></category>
		<guid isPermaLink="false">https://rabbitzlabs.de/cve-2025-15504-lief-project-lief-elf-binary-parser-tcc-parse_binary-null-pointer-dereference/</guid>

					<description><![CDATA[<div>Information published.</div>]]></description>
										<content:encoded><![CDATA[<div>Information published.</div>
<hr>
<p><strong>Quelle:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-15504" target="_blank">CVE-2025-15504 lief-project LIEF ELF Binary Parser.tcc parse_binary null pointer dereference</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CVE-2024-36137 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the &#8211;allow-fs-write flag is used.

Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a &#8222;read-only&#8220; file descriptor to change the owner and permissions of a file.</title>
		<link>https://rabbitzlabs.de/cve-2024-36137-a-vulnerability-has-been-identified-in-node-js-affecting-users-of-the-experimental-permission-model-when-the-allow-fs-write-flag-is-used-node-js-permission-model-do-not-operate-o/</link>
		
		<dc:creator><![CDATA[BlackRabbitZ]]></dc:creator>
		<pubDate>Sun, 31 May 2026 08:48:30 +0000</pubDate>
				<category><![CDATA[CVE]]></category>
		<category><![CDATA[Common Vulnerabilities]]></category>
		<category><![CDATA[exploitability]]></category>
		<category><![CDATA[exploitable]]></category>
		<category><![CDATA[Exposures]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Sicherheitslücken]]></category>
		<guid isPermaLink="false">https://rabbitzlabs.de/cve-2024-36137-a-vulnerability-has-been-identified-in-node-js-affecting-users-of-the-experimental-permission-model-when-the-allow-fs-write-flag-is-used-node-js-permission-model-do-not-operate-o/</guid>

					<description><![CDATA[<div>Information published.</div>]]></description>
										<content:encoded><![CDATA[<div>Information published.</div>
<hr>
<p><strong>Quelle:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-36137" target="_blank"></p>
<div>CVE-2024-36137 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the &#8211;allow-fs-write flag is used.</p>
<p>Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a &#8222;read-only&#8220; file descriptor to change the owner and permissions of a file.</p></div>
<p></a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CVE-2024-22018 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the &#8211;allow-fs-read flag is used.
This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.
This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21.
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.</title>
		<link>https://rabbitzlabs.de/cve-2024-22018-a-vulnerability-has-been-identified-in-node-js-affecting-users-of-the-experimental-permission-model-when-the-allow-fs-read-flag-is-used-this-flaw-arises-from-an-inadequate-permissio/</link>
		
		<dc:creator><![CDATA[BlackRabbitZ]]></dc:creator>
		<pubDate>Sun, 31 May 2026 08:34:40 +0000</pubDate>
				<category><![CDATA[CVE]]></category>
		<category><![CDATA[Common Vulnerabilities]]></category>
		<category><![CDATA[exploitability]]></category>
		<category><![CDATA[exploitable]]></category>
		<category><![CDATA[Exposures]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Sicherheitslücken]]></category>
		<guid isPermaLink="false">https://rabbitzlabs.de/cve-2024-22018-a-vulnerability-has-been-identified-in-node-js-affecting-users-of-the-experimental-permission-model-when-the-allow-fs-read-flag-is-used-this-flaw-arises-from-an-inadequate-permissio/</guid>

					<description><![CDATA[<div>Information published.</div>]]></description>
										<content:encoded><![CDATA[<div>Information published.</div>
<hr>
<p><strong>Quelle:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-22018" target="_blank">CVE-2024-22018 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the &#8211;allow-fs-read flag is used.<br />
This flaw arises from an inadequate permission model that fails to restrict file stats through the fs.lstat API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.<br />
This vulnerability affects all users using the experimental permission model in Node.js 20 and Node.js 21.<br />
Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CVE-2017-3736 There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.</title>
		<link>https://rabbitzlabs.de/cve-2017-3736-there-is-a-carry-propagating-bug-in-the-x86_64-montgomery-squaring-procedure-in-openssl-before-1-0-2m-and-1-1-0-before-1-1-0g-no-ec-algorithms-are-affected-analysis-suggests-that-attac/</link>
		
		<dc:creator><![CDATA[BlackRabbitZ]]></dc:creator>
		<pubDate>Sun, 31 May 2026 08:18:06 +0000</pubDate>
				<category><![CDATA[CVE]]></category>
		<category><![CDATA[Common Vulnerabilities]]></category>
		<category><![CDATA[exploitability]]></category>
		<category><![CDATA[exploitable]]></category>
		<category><![CDATA[Exposures]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Sicherheitslücken]]></category>
		<guid isPermaLink="false">https://rabbitzlabs.de/cve-2017-3736-there-is-a-carry-propagating-bug-in-the-x86_64-montgomery-squaring-procedure-in-openssl-before-1-0-2m-and-1-1-0-before-1-1-0g-no-ec-algorithms-are-affected-analysis-suggests-that-attac/</guid>

					<description><![CDATA[<div>Information published.</div>]]></description>
										<content:encoded><![CDATA[<div>Information published.</div>
<hr>
<p><strong>Quelle:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2017-3736" target="_blank">CVE-2017-3736 There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CVE-2026-28387 Potential Use-after-free in DANE Client Code</title>
		<link>https://rabbitzlabs.de/cve-2026-28387-potential-use-after-free-in-dane-client-code/</link>
		
		<dc:creator><![CDATA[BlackRabbitZ]]></dc:creator>
		<pubDate>Sun, 31 May 2026 08:18:05 +0000</pubDate>
				<category><![CDATA[CVE]]></category>
		<category><![CDATA[Common Vulnerabilities]]></category>
		<category><![CDATA[exploitability]]></category>
		<category><![CDATA[exploitable]]></category>
		<category><![CDATA[Exposures]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Sicherheitslücken]]></category>
		<guid isPermaLink="false">https://rabbitzlabs.de/cve-2026-28387-potential-use-after-free-in-dane-client-code/</guid>

					<description><![CDATA[<div>Information published.</div>]]></description>
										<content:encoded><![CDATA[<div>Information published.</div>
<hr>
<p><strong>Quelle:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-28387" target="_blank">CVE-2026-28387 Potential Use-after-free in DANE Client Code</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CVE-2026-31789 Heap Buffer Overflow in Hexadecimal Conversion</title>
		<link>https://rabbitzlabs.de/cve-2026-31789-heap-buffer-overflow-in-hexadecimal-conversion/</link>
		
		<dc:creator><![CDATA[BlackRabbitZ]]></dc:creator>
		<pubDate>Sun, 31 May 2026 08:18:05 +0000</pubDate>
				<category><![CDATA[CVE]]></category>
		<category><![CDATA[Common Vulnerabilities]]></category>
		<category><![CDATA[exploitability]]></category>
		<category><![CDATA[exploitable]]></category>
		<category><![CDATA[Exposures]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Sicherheitslücken]]></category>
		<guid isPermaLink="false">https://rabbitzlabs.de/cve-2026-31789-heap-buffer-overflow-in-hexadecimal-conversion/</guid>

					<description><![CDATA[<div>Information published.</div>]]></description>
										<content:encoded><![CDATA[<div>Information published.</div>
<hr>
<p><strong>Quelle:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-31789" target="_blank">CVE-2026-31789 Heap Buffer Overflow in Hexadecimal Conversion</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>CVE-2026-28388 NULL Pointer Dereference When Processing a Delta CRL</title>
		<link>https://rabbitzlabs.de/cve-2026-28388-null-pointer-dereference-when-processing-a-delta-crl/</link>
		
		<dc:creator><![CDATA[BlackRabbitZ]]></dc:creator>
		<pubDate>Sun, 31 May 2026 08:18:04 +0000</pubDate>
				<category><![CDATA[CVE]]></category>
		<category><![CDATA[Common Vulnerabilities]]></category>
		<category><![CDATA[exploitability]]></category>
		<category><![CDATA[exploitable]]></category>
		<category><![CDATA[Exposures]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Sicherheitslücken]]></category>
		<guid isPermaLink="false">https://rabbitzlabs.de/cve-2026-28388-null-pointer-dereference-when-processing-a-delta-crl/</guid>

					<description><![CDATA[<div>Information published.</div>]]></description>
										<content:encoded><![CDATA[<div>Information published.</div>
<hr>
<p><strong>Quelle:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-28388" target="_blank">CVE-2026-28388 NULL Pointer Dereference When Processing a Delta CRL</a></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
