...
...

Technical Advisory

Through sharp, technical and insightful analysis, the Payatu Team is constantly on the lookout for vulnerabilities and threats. This section exhibits a few of our findings.

Report ID Title Reporeted On Publish On CVE-ID
PS1 Microsoft Edge Elevation of Privilege Vulnerability 28-Nov-2018 03-Dec-2019 CVE-2019-0678
PS2 Adobe Reader Out-Of-Bounds Read Information Disclosure Vulnerability 08-Jan-2018 01-Oct-2018 CVE-2018-15968
PS3 Opera Mini Location Permission Spoof 02-Aug-2018 18-Aug-2018 CVE-2018-16135
PS4 Foxit Reader - CPDF_Parser::m_pCryptoHandler - Use After Free - RCE 08-Jan-2018 16-Aug-2018 CVE-2018-14442
PS5 jscript.dll - ActiveXObject BSTR - Use After Free 09-Jan-2018 14-Aug-2018 CVE-2018-8389
PS6 Adobe Acrobat Reader Heap Overflow Remote Code Execution Vulnerability 08-Jan-2018 10-Jul-2018 CVE-2018-12798
PS7 Foxit Reader PDF Parsing Out-Of-Bounds Read Information Disclosure Vulnerability 19-Jan-2018 20-Apr-2018 CVE-2018-9950
PS8 Foxit Reader CPDF_Object Use-After-Free Remote Code Execution Vulnerability 19-Jan-2018 20-Apr-2018 CVE-2018-9951
PS9 Foxit Reader – Uninitialized Memory – Arbitrary Write Vulnerability 05-May-2017 07-Jul-2017 CVE-2017-10994
PS10 Foxit Reader PDF Parsing Out-Of-Bounds Read Information Disclosure Vulnerability 18-May-2017 07-Jul-2017 CVE-2017-10942
PS11 Foxit Reader PDF Parsing Out-Of-Bounds Read Information Disclosure Vulnerability 01-Jun-2017 07-Jul-2017 CVE-2017-10944
PS12 Foxit Reader PDF Parsing Out-Of-Bounds Read Information Disclosure Vulnerability 18-May-2017 07-Jul-2017 CVE-2017-10943
PS13 Foxit Reader Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability 03-Jan-2017 09-Mar-2017 CVE-2017-8453
PS14 Out of Bounds Write Heap Buffer Google Chrome PDFium 25-Nov-2016 09-Mar-2017 CVE-2017-5032
PS15 Foxit Reader PDF Parsing Out-Of-Bounds Read Information Disclosure Vulnerability 22-Feb-2017 09-Mar-2017 CVE-2017-8455
PS16 Foxit Reader PDF Parsing Out-Of-Bounds Read Information Disclosure Vulnerability 03-Jan-2017 09-Mar-2017 CVE-2017-8454
PS17 Memory Corruption Mach-O 2 25-Jun-2016 05-Aug-2016 CVE-2017-8775
PS18 Non-ASLR & DEP Modules 09-Jun-2016 01-Aug-2016 CVE-2017-8776
PS19 Insecure Libray Loading 09-Jun-2016 01-Aug-2016
PS20 OOB Write Heap Buffer dwCompressionSize MS-WIM 13-Jul-2016 20-Jul-2016 CVE-2017-8773
PS21 Memory Corruption Mach-O 1 25-Jun-2016 11-Jul-2016 CVE-2017-8774
PS22 OOB Write Stack Buffer LC_UNIXTHREAD.cmdsize Mach-O 09-Jun-2016 11-Jun-2016 CVE-2017-5005
PS23 Adobe Reader Type Confusion - Memory Corruption Vulnerability 05-Dec-2016 06-Apr-2016 CVE-2017-3038
PS24 Microsoft Internet Explorer CDOMStringDataList::InitFromString Out-Of-Bounds Indexing Information Disclosure Vulnerability 08-Sep-2015 10-Nov-2015 CVE-2015-6086
PS25 Hardcoded AES 256 bit key used in Kankun Smart socket and its mobile App 25-May-2015 05-Jun-2015 CVE-2015-4080
PS26 CVE-2014-8446 – Adobe Acrobat/Reader – Memory Corruption 15-May-2014 09-Dec-2014 CVE-2014-8446

Latest news See all news

30-December-2019
Leipzig, Germany

Visit

Nikhil Mittal will be speaking at CCC events on the topic breaking Microsoft edge extensions security policies 

29-November-2019
Seoul, Korea

Visit

Ashfaq Ansari a.k.a "HackSysTeam", will be delivering Windows Kernel Exploitation Training.

09-October-2019
Delhi, India

Visit

Sudhakar Verma and Krishnakant Patil will be delivering 2 days training on Reverse Engineering at NULLCON Delhi 2019.