Hossein Lotfi: Senior Vulnerability Researcher at Zero Day Initiative
X (Twitter)
Linkedin
- CVE-2023-38600: STORY OF AN INNOCENT APPLE SAFARI COPYWITHIN GONE (WAY) OUTSIDE
- BUT YOU TOLD ME YOU WERE SAFE: ATTACKING THE MOZILLA FIREFOX SANDBOX (PART 2)
- BUT BUT YOU TOLD ME YOU WERE SAFE: ATTACKING THE MOZILLA FIREFOX RENDERER (PART 1)
- CVE-2022-26381: GONE BY OTHERS! TRIGGERING A UAF IN FIREFOX
- EXPLOITATION OF CVE-2021-21220 – FROM INCORRECT JIT BEHAVIOR TO RCE
- UNDERSTANDING THE ROOT CAUSE OF CVE-2021-21220 – A CHROME BUG FROM PWN2OWN 2021
- TWO BIRDS WITH ONE STONE: AN INTRODUCTION TO V8 AND JIT EXPLOITATION
- CVE-2021-31969: UNDERFLOWING IN THE CLOUDS
- SYNCING OUT OF THE FIREFOX SANDBOX
- THE LEFT BRANCH LESS TRAVELLED: A STORY OF A MOZILLA FIREFOX USE-AFTER-FREE VULNERABILITY
- THE STORY OF TWO WINNING PWN2OWN JIT VULNERABILITIES IN MOZILLA FIREFOX
- Microsoft Windows "LoadUvsTable()" Heap-based Buffer Overflow Vulnerability
- A Look into Microsoft Windows usp10.dll "GetFontDesc()" Integer Underflow Vulnerability
- Yet Another Windows GDI Story - MS15-035
- In Memory of a Zero-day - MS13-051