CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
268 results Clear all
CVE-2017-14932 5.5 MEDIUM EPSS 0.00
GNU Binutils 2.29 - DoS
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file.
CWE-835 Sep 30, 2017
CVE-2017-14930 5.5 MEDIUM EPSS 0.00
GNU Binutils 2.29 - Memory Corruption
Memory leak in decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
CWE-772 Sep 30, 2017
CVE-2017-14745 7.8 HIGH EPSS 0.00
GNU Binutils 2.29 - DoS
The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, interpret a -1 value as a sorting count instead of an error flag, which allows remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, related to elf32-i386.c and elf64-x86-64.c.
CWE-190 Sep 26, 2017
CVE-2017-14729 7.8 HIGH EPSS 0.00
GNU Binutils 2.29 - DoS
The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, do not ensure a unique PLT entry for a symbol, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, related to elf32-i386.c and elf64-x86-64.c.
CWE-119 Sep 25, 2017
CVE-2017-14529 5.5 MEDIUM EPSS 0.00
GNU Binutils 2.29 - Heap-Based Buffer Over-Read
The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles HintName vector entries, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PE file, related to the bfd_getl16 function.
CWE-125 Sep 18, 2017
CVE-2017-14333 7.8 HIGH EPSS 0.00
GNU Binutils 2.29 - DoS
The process_version_sections function in readelf.c in GNU Binutils 2.29 allows attackers to cause a denial of service (Integer Overflow, and hang because of a time-consuming loop) or possibly have unspecified other impact via a crafted binary file with invalid values of ent.vn_next, during "readelf -a" execution.
CWE-190 Sep 12, 2017
CVE-2017-14130 5.5 MEDIUM EPSS 0.00
GNU Binutils 2.29 - DoS
The _bfd_elf_parse_attributes function in elf-attrs.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (_bfd_elf_attr_strdup heap-based buffer over-read and application crash) via a crafted ELF file.
CWE-125 Sep 04, 2017
CVE-2017-14129 5.5 MEDIUM EPSS 0.00
GNU Binutils 2.29 - DoS
The read_section function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (parse_comp_unit heap-based buffer over-read and application crash) via a crafted ELF file.
CWE-125 Sep 04, 2017
CVE-2017-14128 5.5 MEDIUM EPSS 0.00
GNU Binutils 2.29 - DoS
The decode_line_info function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (read_1_byte heap-based buffer over-read and application crash) via a crafted ELF file.
CWE-125 Sep 04, 2017
CVE-2017-13757 5.5 MEDIUM EPSS 0.00
GNU Binutils - Out-of-Bounds Read
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the PLT section size, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to elf_i386_get_synthetic_symtab in elf32-i386.c and elf_x86_64_get_synthetic_symtab in elf64-x86-64.c.
CWE-125 Aug 29, 2017
CVE-2017-13716 5.5 MEDIUM EPSS 0.00
GNU Binutils - Resource Allocation Without Limits
The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).
CWE-770 Aug 28, 2017
CVE-2017-13710 7.5 HIGH EPSS 0.01
GNU Binutils - NULL Pointer Dereference
The setup_group function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a group section that is too small.
CWE-476 Aug 27, 2017
CVE-2017-12967 6.5 MEDIUM EPSS 0.01
GNU Binutils - Out-of-Bounds Read
The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a malformed tekhex binary.
CWE-125 Aug 19, 2017
CVE-2017-12799 7.8 HIGH EPSS 0.00
GNU Binutils - Memory Corruption
The elf_read_notesfunction in bfd/elf.c in GNU Binutils 2.29 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file.
CWE-119 Aug 10, 2017
CVE-2017-12459 7.8 HIGH EPSS 0.01
GNU Binutils < 2.29 - Out-of-Bounds Write
The bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted mach-o file.
CWE-787 Aug 04, 2017
CVE-2017-12458 7.8 HIGH EPSS 0.00
GNU Binutils < 2.29 - Out-of-Bounds Read
The nlm_swap_auxiliary_headers_in function in bfd/nlmcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted nlm file.
CWE-125 Aug 04, 2017
CVE-2017-12457 7.8 HIGH EPSS 0.00
GNU Binutils < 2.29 - NULL Pointer Dereference
The bfd_make_section_with_flags function in section.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a NULL dereference via a crafted file.
CWE-476 Aug 04, 2017
CVE-2017-12456 7.8 HIGH EPSS 0.00
GNU Binutils < 2.29 - Out-of-Bounds Read
The read_symbol_stabs_debugging_info function in rddbg.c in GNU Binutils 2.29 and earlier allows remote attackers to cause an out of bounds heap read via a crafted binary file.
CWE-125 Aug 04, 2017
CVE-2017-12455 7.8 HIGH EPSS 0.00
GNU Binutils < 2.29 - Out-of-Bounds Read
The evax_bfd_print_emh function in vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.
CWE-125 Aug 04, 2017
CVE-2017-12454 7.8 HIGH EPSS 0.00
GNU Binutils < 2.29 - Out-of-Bounds Read
The _bfd_vms_slurp_egsd function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an arbitrary memory read via a crafted vms alpha file.
CWE-125 Aug 04, 2017