CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,847 CVEs tracked 53,242 with exploits 4,725 exploited in wild 1,540 CISA KEV 3,918 Nuclei templates 37,802 vendors 42,493 researchers
266 results Clear all
CVE-2025-1147 3.1 LOW EPSS 0.00
GNU Binutils - Memory Corruption
A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CWE-119 Feb 10, 2025
CVE-2025-0840 5.0 MEDIUM EPSS 0.00
GNU Binutils < 2.44 - Out-of-Bounds Write
A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.
CWE-119 Jan 29, 2025
CVE-2023-25588 4.7 MEDIUM EPSS 0.00
GNU Binutils - Use of Uninitialized Resource
A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service.
CWE-457 Sep 14, 2023
CVE-2023-25586 4.7 MEDIUM EPSS 0.00
GNU Binutils - Use of Uninitialized Resource
A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service.
CWE-457 Sep 14, 2023
CVE-2023-25585 4.7 MEDIUM EPSS 0.00
GNU Binutils - Use of Uninitialized Resource
A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
CWE-457 Sep 14, 2023
CVE-2023-25584 6.3 MEDIUM EPSS 0.00
GNU Binutils < 2.40 - Out-of-Bounds Read
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
CWE-125 Sep 14, 2023
CVE-2022-48065 5.5 MEDIUM EPSS 0.00
GNU Binutils < 2.40 - Memory Leak
GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c.
CWE-401 Aug 22, 2023
CVE-2022-48064 5.5 MEDIUM EPSS 0.00
GNU Binutils < 2.40 - Resource Allocation Without Limits
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
CWE-770 Aug 22, 2023
CVE-2022-48063 5.5 MEDIUM EPSS 0.00
GNU Binutils < 2.40 - Denial of Service
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
CWE-400 Aug 22, 2023
CVE-2022-47696 7.8 HIGH EPSS 0.00
GNU Binutils < 2.39.3 - Denial of Service
An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols.
CWE-400 Aug 22, 2023
CVE-2022-47695 7.8 HIGH EPSS 0.00
GNU Binutils < 2.39.3 - Denial of Service
An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c.
CWE-400 Aug 22, 2023
CVE-2022-47673 7.8 HIGH EPSS 0.00
GNU Binutils < 2.39.3 - Out-of-Bounds Read
An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts.
CWE-125 Aug 22, 2023
CVE-2022-47011 5.5 MEDIUM EPSS 0.00
Binutils <2.39 - DoS
An issue was discovered function parse_stab_struct_fields in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
CWE-401 Aug 22, 2023
CVE-2022-47010 5.5 MEDIUM EPSS 0.00
Binutils <2.39 - DoS
An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
CWE-401 Aug 22, 2023
CVE-2022-47008 5.5 MEDIUM EPSS 0.00
Binutils <2.39 - DoS
An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
CWE-401 Aug 22, 2023
CVE-2022-47007 5.5 MEDIUM EPSS 0.00
Binutils <2.39 - DoS
An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
CWE-401 Aug 22, 2023
CVE-2022-45703 7.8 HIGH EPSS 0.00
GNU Binutils < 2.40 - Out-of-Bounds Write
Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.
CWE-787 Aug 22, 2023
CVE-2022-44840 7.8 HIGH EPSS 0.00
GNU Binutils < 2.40 - Out-of-Bounds Write
Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c.
CWE-787 Aug 22, 2023
CVE-2022-35206 5.5 MEDIUM EPSS 0.00
GNU Binutils - NULL Pointer Dereference
Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c.
CWE-476 Aug 22, 2023
CVE-2022-35205 5.5 MEDIUM EPSS 0.00
GNU Binutils - Reachable Assertion
An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service.
CWE-617 Aug 22, 2023