top | item 24729356

(no title)

kingkilr | 5 years ago

I don't have any data on exploitability, but 19 of the last 22 vulnerabilities (since 2018) have C-induced memory unsafety as a cause: https://curl.haxx.se/docs/security.html

discuss

order

mehrdadn|5 years ago

Oh thanks, that at least gives some idea of the potential. I see e.g. "HTTP/2 trailer out-of-bounds read" and "SSL out of buffer access"... I guess there might be some candidates.

pjmlp|5 years ago

If you start from when Morris worm got released into UNIX world, there will be plenty to chose from.