CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
268 results Clear all
CVE-2017-12453 7.8 HIGH EPSS 0.00
GNU Binutils < 2.29 - Out-of-Bounds Read
The _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.
CWE-125 Aug 04, 2017
CVE-2017-12452 7.8 HIGH EPSS 0.00
GNU Binutils < 2.29 - Out-of-Bounds Read
The bfd_mach_o_i386_canonicalize_one_reloc function in bfd/mach-o-i386.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted mach-o file.
CWE-125 Aug 04, 2017
CVE-2017-12451 7.8 HIGH EPSS 0.00
GNU Binutils < 2.29 - Out-of-Bounds Read
The _bfd_xcoff_read_ar_hdr function in bfd/coff-rs6000.c and bfd/coff64-rs6000.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds stack read via a crafted COFF image file.
CWE-125 Aug 04, 2017
CVE-2017-12450 7.8 HIGH EPSS 0.01
GNU Binutils < 2.29 - Out-of-Bounds Write
The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted vms alpha file.
CWE-787 Aug 04, 2017
CVE-2017-12449 7.8 HIGH EPSS 0.00
GNU Binutils < 2.29 - Out-of-Bounds Read
The _bfd_vms_save_sized_string function in vms-misc.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms file.
CWE-125 Aug 04, 2017
CVE-2017-12448 7.8 HIGH EPSS 0.01
GNU Binutils < 2.29 - Use After Free
The bfd_cache_close function in bfd/cache.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a heap use after free and possibly achieve code execution via a crafted nested archive file. This issue occurs because incorrect functions are called during an attempt to release memory. The issue can be addressed by better input validation in the bfd_generic_archive_p function in bfd/archive.c.
CWE-416 Aug 04, 2017
CVE-2017-9955 5.5 MEDIUM EPSS 0.00
GNU Binutils - Out-of-Bounds Read
The get_build_id function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file in which a certain size field is larger than a corresponding data field, as demonstrated by mishandling within the objdump program.
CWE-125 Jun 26, 2017
CVE-2017-9954 5.5 MEDIUM EPSS 0.00
GNU Binutils - Out-of-Bounds Read
The getvalue function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted tekhex file, as demonstrated by mishandling within the nm program.
CWE-125 Jun 26, 2017
CVE-2017-9756 7.8 HIGH 1 PoC Analysis EPSS 0.03
GNU Binutils 2.28 - Buffer Overflow
The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
CWE-119 Jun 19, 2017
CVE-2017-9755 7.8 HIGH EPSS 0.01
GNU Binutils 2.28 - DoS
opcodes/i386-dis.c in GNU Binutils 2.28 does not consider the number of registers for bnd mode, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
CWE-119 Jun 19, 2017
CVE-2017-9754 7.8 HIGH EPSS 0.01
GNU Binutils 2.28 - DoS
The process_otr function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not validate a certain offset, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
CWE-119 Jun 19, 2017
CVE-2017-9753 7.8 HIGH EPSS 0.01
GNU Binutils 2.28 - DoS
The versados_mkobject function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not initialize a certain data structure, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
CWE-119 Jun 19, 2017
CVE-2017-9752 7.8 HIGH EPSS 0.01
GNU Binutils 2.28 - DoS
bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file in the _bfd_vms_get_value and _bfd_vms_slurp_etir functions during "objdump -D" execution.
CWE-119 Jun 19, 2017
CVE-2017-9751 7.8 HIGH EPSS 0.01
GNU Binutils 2.28 - DoS
opcodes/rl78-decode.opc in GNU Binutils 2.28 has an unbounded GETBYTE macro, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
CWE-119 Jun 19, 2017
CVE-2017-9750 7.8 HIGH 1 PoC Analysis EPSS 0.03
GNU Binutils 2.28 - Buffer Overflow
opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
CWE-119 Jun 19, 2017
CVE-2017-9749 7.8 HIGH 1 PoC Analysis EPSS 0.05
GNU Binutils <2.28 - DoS
The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
CWE-119 Jun 19, 2017
CVE-2017-9748 7.8 HIGH 1 PoC Analysis EPSS 0.03
GNU Binutils 2.28 - DoS
The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. NOTE: this may be related to a compiler bug.
CWE-119 Jun 19, 2017
CVE-2017-9747 7.8 HIGH 1 PoC Analysis EPSS 0.02
GNU Binutils 2.28 - DoS
The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. NOTE: this may be related to a compiler bug.
CWE-119 Jun 19, 2017
CVE-2017-9746 7.8 HIGH 1 PoC Analysis EPSS 0.05
GNU Binutils 2.28 - DoS
The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of rae insns printing for this file during "objdump -D" execution.
CWE-119 Jun 19, 2017
CVE-2017-9745 7.8 HIGH EPSS 0.01
GNU Binutils 2.28 - DoS
The _bfd_vms_slurp_etir function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
CWE-119 Jun 19, 2017