<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0xSemizzz | Yehia Ezzat</title><description>0xSemizzz is the alias of Yehia Ezzat, an Egyptian Computer Science student at The British University in Egypt (BUE) and security researcher focused on vulnerability research, open source security, and low-level systems.</description><link>https://0xsemizzz.vercel.app/</link><language>en-us</language><item><title>Four Hours, Four Bytes: Hunting Down CVE-2026-18649</title><link>https://0xsemizzz.vercel.app/blog/hunting-cve-2026-18649-gstreamer-rtp/</link><guid isPermaLink="true">https://0xsemizzz.vercel.app/blog/hunting-cve-2026-18649-gstreamer-rtp/</guid><description>The full story of finding an unbounded memory growth bug in GStreamer&apos;s RTP depayloader, including the seven attempts that failed before the exploit worked.</description><pubDate>Thu, 06 Aug 2026 00:00:00 GMT</pubDate></item><item><title>CVE-2026-18649: Unbounded Memory Growth in GStreamer&apos;s RTP Depayloaders</title><link>https://0xsemizzz.vercel.app/blog/cve-2026-18649-gstreamer-rtp-dos/</link><guid isPermaLink="true">https://0xsemizzz.vercel.app/blog/cve-2026-18649-gstreamer-rtp-dos/</guid><description>A technical breakdown of a remote, unauthenticated denial of service in GStreamer&apos;s H.264 and H.265 RTP depayloaders, where FU-A fragment reassembly had no size limit.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate></item></channel></rss>