CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,223 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,429 researchers
392 results Clear all
CVE-2011-2497 EPSS 0.03
Linux Kernel < 3.0 - Integer Underflow
Integer underflow in the l2cap_config_req function in net/bluetooth/l2cap_core.c in the Linux kernel before 3.0 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a small command-size value within the command header of a Logical Link Control and Adaptation Protocol (L2CAP) configuration request, leading to a buffer overflow.
CWE-191 Aug 29, 2011
CVE-2011-1770 7.5 HIGH EPSS 0.05
Linux kernel <2.6.33.14 - DoS
Integer underflow in the dccp_parse_options function (net/dccp/options.c) in the Linux kernel before 2.6.33.14 allows remote attackers to cause a denial of service via a Datagram Congestion Control Protocol (DCCP) packet with an invalid feature options length, which triggers a buffer over-read.
CWE-191 Jun 24, 2011
CVE-2010-4529 EPSS 0.00
Linux Kernel < 2.6.37 - Integer Underflow
Integer underflow in the irda_getsockopt function in net/irda/af_irda.c in the Linux kernel before 2.6.37 on platforms other than x86 allows local users to obtain potentially sensitive information from kernel heap memory via an IRLMP_ENUMDEVICES getsockopt call.
CWE-191 Jan 13, 2011
CVE-2010-4164 EPSS 0.02
Linux Kernel < 2.6.36.2 - Integer Underflow
Multiple integer underflows in the x25_parse_facilities function in net/x25/x25_facilities.c in the Linux kernel before 2.6.36.2 allow remote attackers to cause a denial of service (system crash) via malformed X.25 (1) X25_FAC_CLASS_A, (2) X25_FAC_CLASS_B, (3) X25_FAC_CLASS_C, or (4) X25_FAC_CLASS_D facility data, a different vulnerability than CVE-2010-3873.
CWE-191 Jan 03, 2011
CVE-2010-2497 EPSS 0.02
Freetype < 2.4.0 - Integer Underflow
Integer underflow in glyph handling in FreeType before 2.4.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font file.
CWE-191 Aug 19, 2010
CVE-2009-3301 EPSS 0.43
Apache Openoffice < 3.2.0 - Integer Underflow
Integer underflow in filter/ww8/ww8par2.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted sprmTDefTable table property modifier in a Word document.
CWE-191 Feb 16, 2010
CVE-2007-0063 EPSS 0.08
Vmware Esx < 1.0.3 - Integer Underflow
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.
CWE-191 Sep 21, 2007
CVE-2005-1891 7.5 HIGH EPSS 0.01
AOL Aim < 5.9.3797 - Integer Underflow
The GIF parser in ateimg32.dll in AOL Instant Messenger (AIM) 5.9.3797 and earlier allows remote attackers to cause a denial of service (crash) via a malformed buddy icon that causes an integer underflow in a loop counter variable.
CWE-191 Jun 09, 2005
CVE-2005-0199 9.8 CRITICAL 1 PoC Analysis EPSS 0.20
Barton Ngircd < 0.8.2 - Integer Underflow
Integer underflow in the Lists_MakeMask() function in lists.c in ngIRCd before 0.8.2 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MODE line that causes an incorrect length calculation, which leads to a buffer overflow.
CWE-191 May 02, 2005
CVE-2004-1002 7.5 HIGH EPSS 0.02
ppp 2.4.1 - DoS
Integer underflow in pppd in cbcp.c for ppp 2.4.1 allows remote attackers to cause a denial of service (daemon crash) via a CBCP packet with an invalid length value that causes pppd to access an incorrect memory location.
CWE-191 Mar 01, 2005
CVE-2004-0816 7.5 HIGH 1 PoC Analysis EPSS 0.07
Linux <2.6.8 - DoS
Integer underflow in the firewall logging rules for iptables in Linux before 2.6.8 allows remote attackers to cause a denial of service (application crash) via a malformed IP packet.
CWE-191 Dec 23, 2004
CVE-2004-0184 1 PoC Analysis EPSS 0.65
Tcpdump < 3.8.1 - Integer Underflow
Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an ISAKMP packet with an Identification payload with a length that becomes less than 8 during byte order conversion, which causes an out-of-bounds read, as demonstrated by the Striker ISAKMP Protocol Test Suite.
CWE-125 May 04, 2004