1. aaron(7)
  2. aaron(7)

NAME

aaron - hacker, researcher, reverse engineer

SYNOPSIS

aaron [--reverser]
aaron [--exploiter]
aaron [--presenter]
aaron [--educator]
aaron [--author]
aaron [--commentator]
aaron [--guest]

DESCRIPTION

Aaron Portnoy is a security researcher, reverse engineer, speaker, and educator.
This page serves as a minimalist reference to his work and interests.

OPTIONS

PRESENTATIONS

PUBLICATIONS

PRESS

PODCASTS

CITATIONS

VULNERABILITIES

CVE-2026-41153
JetBrains Junie: command injection via malicious project file enabling unsafe command execution
CVE-2026-0612
The Librarian: information leakage via web_fetch tool in AI assistant
CVE-2026-0613
The Librarian: internal port scanning via AI assistant
CVE-2026-0615
The Librarian: unauthorized access to supervisord status page via AI assistant
CVE-2026-0616
The Librarian: unauthorized access to Adminer database interface via AI assistant
CVE-2025-68432
Zed IDE: arbitrary code execution via malicious LSP binary configuration in .zed/settings.json
CVE-2025-68433
Zed IDE: command injection via MCP configuration
Eclipse Theia MCP
MCP configuration vulnerability in Eclipse Theia IDE
Cline
DNS-based data exfiltration via prompt injection in source file docstrings, coercing reads of .env files and exfiltrating secrets via DNS queries
Cline
arbitrary code execution via prompt injection in .clinerules config file, bypassing user approval dialogs
Cline
TOCTOU race condition via sequential prompt injection enabling arbitrary code execution across separate interaction windows
Cline
model identity disclosure via error messages revealing underlying AI model
Aider
zero-click arbitrary command execution via malicious .aider.conf.yml loading an external command file with user prompts suppressed
CVE-2021-3064
Palo Alto GlobalProtect: stack-based buffer overflow enabling unauthenticated RCE in portal and gateway interfaces; Randori Attack Team
CVE-2017-13997
Schneider Electric InduSoft Web Studio / InTouch Machine Edition: missing authentication enabling arbitrary command execution, CVSS 9.8
CVE-2017-14024
Schneider Electric InduSoft Web Studio / InTouch Machine Edition: stack-based buffer overflow enabling RCE, CVSS 9.8
CVE-2017-8022
EMC NetWorker: buffer overflow in nsrd service enabling unauthenticated RCE
CVE-2013-0657
Schneider Electric IGSS: stack-based buffer overflow via TCP port 12397, CVSS 10.0
CVE-2013-0658
Schneider Electric Accutech Manager: heap-based buffer overflow in RFManagerService.exe, CVSS 10.0
CVE-2012-4704
3S CODESYS Gateway-Server: array index error enabling RCE
CVE-2012-4705
3S CODESYS Gateway-Server: directory traversal enabling arbitrary code execution
CVE-2012-4706
3S CODESYS Gateway-Server: integer signedness error causing heap buffer overflow
CVE-2012-4707
3S CODESYS Gateway-Server: out-of-bounds memory access enabling code injection
CVE-2012-4708
3S CODESYS Gateway-Server: stack-based buffer overflow enabling RCE
CVE-2012-2288
EMC NetWorker: format string vulnerability in nsrd RPC service enabling RCE
CVE-2012-0121
HP Data Protector Express: unspecified vulnerability enabling RCE or DoS, CVSS 10.0
CVE-2012-0122
HP Data Protector Express: unspecified vulnerability enabling RCE or DoS, CVSS 10.0
CVE-2012-0123
HP Data Protector Express: unspecified vulnerability enabling RCE or DoS, CVSS 10.0
CVE-2012-0124
HP Data Protector Express: unspecified vulnerability enabling RCE or DoS, CVSS 10.0
Oracle CPU
multiple Oracle product vulnerabilities
CVE-2011-4185
Novell iPrint Client: ActiveX GetPrinterURLList2 stack-based buffer overflow enabling RCE
CVE-2012-0774
Adobe Reader X: True Type Font MINDEX table integer overflow enabling RCE
CVE-2012-1182
Samba: NDR PULL EVENTLOG heap overflow enabling RCE
CVE-2012-0549
Oracle AutoVue: ActiveX SetMarkupMode enabling RCE
TPTI-12-01
Oracle Java: True Type Font IDEF opcode parsing enabling RCE
CVE-2011-0335
Adobe Shockwave Player: memory buffer overflow enabling RCE
CVE-2011-0555
Adobe Shockwave Player: memory buffer overflow enabling RCE
CVE-2011-0556
Adobe Shockwave Player: memory buffer overflow enabling RCE
CVE-2011-0569
Adobe Shockwave Player: buffer overflow in Font Xtra.x32 enabling RCE
CVE-2011-2111
Adobe Shockwave Player: buffer overflow in IML32.dll enabling RCE
CVE-2011-2116
Adobe Shockwave Player: memory corruption enabling RCE
CVE-2011-0862
Oracle Java SE: ICC Profile rcs2 tag parsing enabling RCE
TPTI-11-13
McAfee SaaS: myCIOScn.dll scan method script injection enabling RCE
TPTI-11-15
Novell ZENWorks Software Packaging: ISGrid.Grid2.1 bstrSearchText parameter enabling RCE
CVE-2010-2866
Adobe Shockwave Player: integer signedness error in DIRAPI module enabling RCE
CVE-2010-2867
Adobe Shockwave Player: pointer offset vulnerability in DIRAPIX.dll enabling RCE
CVE-2010-2870
Adobe Shockwave Player: heap-based buffer overflow in DIRAPIX.dll enabling RCE
CVE-2010-2874
Adobe Shockwave Player: memory corruption via uninitialized pointer enabling RCE
CVE-2010-2877
Adobe Shockwave Player: improper input validation in Director movie parsing enabling RCE
CVE-2010-2878
Adobe Shockwave Player: improper input validation in DIRAPIX.dll enabling RCE
CVE-2010-2879
Adobe Shockwave Player: integer overflow in TextXtra.x32 enabling RCE
CVE-2010-4188
Adobe Shockwave Player: heap-based buffer overflow enabling RCE
CVE-2010-4189
Adobe Shockwave Player: memory buffer overflow enabling RCE
CVE-2010-3106
Novell iPrint Client: ActiveX control improper input validation enabling RCE
CVE-2010-3107
Novell iPrint Client: logic flaw in file deletion permissions
CVE-2010-4316
Novell iPrint Client: browser plugin Execute Request debug parameter RCE
CVE-2010-4317
Novell iPrint Client: browser plugin GetDriverFile uninitialized pointer RCE
CVE-2010-4319
Novell iPrint Client: remote arbitrary file deletion
CVE-2010-4385
RealNetworks RealPlayer: invalid frame dimensions in SIPR stream enabling RCE
CVE-2010-4390
RealNetworks RealPlayer: heap buffer overflow in MDPR chunk parsing enabling RCE; w/ Logan Brown
CVE-2010-4294
VMware Movie Decoder / Workstation / Player / Server: heap memory corruption enabling code injection
CVE-2010-0034
Microsoft Office PowerPoint Viewer: TextCharsAtom record code execution
CVE-2010-0898
Oracle Secure Backup: Scheduler Service RCE
TPTI-10-01
HP Data Protector Server Cell Manager: RCE
TPTI-10-03
Sophos Anti-Virus: SAVOnAccessFilter local privilege escalation
TPTI-10-05
Novell iPrint Client Browser Plugin: remote file deletion
TPTI-10-07
SAP Crystal Reports 2008: GIOP message size integer overflow enabling RCE
CVE-2009-3846
HP OpenView Network Node Manager: heap-based buffer overflow in ovlogin.exe, CVSS 10.0
CVE-2009-4176
HP OpenView Network Node Manager: heap-based buffer overflow in ovsessionmgr.exe, CVSS 10.0
CVE-2009-4177
HP OpenView Network Node Manager: buffer overflow in webappmon.exe CGI via Host header, CVSS 10.0
CVE-2009-4178
HP OpenView Network Node Manager: heap-based buffer overflow in OvWebHelp.exe via Topic parameter, CVSS 10.0
CVE-2009-4179
HP OpenView Network Node Manager: stack-based buffer overflow in ovalarm.exe via Accept-Language header, CVSS 10.0
CVE-2009-4180
HP OpenView Network Node Manager: stack-based buffer overflow in snmpviewer.exe via Host header, CVSS 10.0
CVE-2009-4181
HP OpenView Network Node Manager: heap-based buffer overflow in OvCgi/Toolbar.exe, CVSS 10.0
CVE-2009-1539
Microsoft DirectShow: size validation vulnerability in QuickTime media file parsing enabling RCE
CVE-2009-0909
VMware Workstation / Player / ACE / Server: heap-based buffer overflow in VNnc Codec enabling RCE
CVE-2009-0910
VMware Workstation / Player / ACE / Server: heap-based buffer overflow in VNnc Codec
CVE-2009-1544
Microsoft Windows Workstation Service: NetrGetJoinInformation heap corruption enabling RCE
CVE-2008-4030
Microsoft Office Word: resource management error in RTF file parsing enabling RCE
CVE-2008-4031
Microsoft Office Word: resource management error in RTF handling enabling RCE
CVE-2008-3479
Microsoft MSMQ: remote code execution via malformed RPC request; w/ Cody Pierce
CVE-2008-2468
LANDesk Management Suite: buffer overflow in QIP Server Service enabling RCE, CVSS 10.0
CVE-2008-0027
Cisco Unified CallManager: CTLProvider heap overflow enabling RCE
CVE-2008-0033
Apple QuickTime: IDSC atom memory corruption enabling RCE
CVE-2007-6242
Adobe Flash Player: improper input validation enabling code execution
CVE-2007-6026
Microsoft Office Access: stack-based buffer overflow in Jet Engine enabling RCE
CVE-2007-5082
CA BrightStor ARCserve Backup HSM: RCE vulnerability; w/ Sean Larsson
CVE-2007-5083
CA BrightStor ARCserve Backup HSM: DoS vulnerability; w/ Sean Larsson
CVE-2007-5084
CA BrightStor ARCserve Backup HSM: RCE vulnerability; w/ Sean Larsson
CVE-2007-5323
EMC Replistor: buffer overflow in server service enabling RCE, CVSS 10.0
CVE-2007-2417
Progress Software OpenEdge: heap-based buffer overflow in _mprosrv.exe, CVSS 10.0
CVE-2007-2280
HP OpenView Data Protector: stack-based buffer overflow in Omnilnet.exe on TCP port 5555
CVE-2007-2279
Symantec Storage Foundation for Windows: authentication bypass enabling arbitrary code execution
CVE-2007-1868
IBM Tivoli Provisioning Manager for OS Deployment: multiple stack overflows in HTTP service enabling RCE
CVE-2007-1862
Apache HTTP Server mod_mem_cache: information disclosure via improper memory handling returning previous request headers
CVE-2007-1676
HP OpenView Shared Trace Service: stack-based buffer overflows in ovtrcsvc.exe and OVTrace.exe via crafted requests to opcode handlers 0x1a and 0x0f
CVE-2007-1674
LANDesk Management Suite: stack-based buffer overflow in Alert Service, CVSS 10.0
CVE-2007-1070
Trend Micro ServerProtect: stack overflows in StCommon.dll and eng50.dll enabling RCE
CVE-2006-5820
America Online SuperBuddy: ActiveX control code execution
CVE-2007-0754
Apple QuickTime: STSD atom heap overflow enabling RCE
CVE-2007-3566
Borland InterBase: ibserver.exe create-request buffer overflow enabling RCE
CVE-2007-4827
Automated Solutions Modbus TCP Slave: ActiveX control heap corruption
CVE-2006-5782
HP OpenView Client Configuration Manager: device code execution vulnerability
CVE-2006-6334
Citrix Presentation Server Client: heap-based buffer overflow

HISTORY

SEE ALSO

Email: aaron@aaronportnoy.com
GitHub: aaronportnoy

  1. May 2026
  2. aaron(7)