Exploit Intelligence Platform

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,497 CVEs tracked 53,352 with exploits 4,748 exploited in wild 1,551 CISA KEV 3,947 Nuclei templates 49,202 vendors 42,818 researchers
111,546 results Clear all
CVE-2017-9257 5.5 MEDIUM EPSS 0.00
Freeware Advanced Audio Decoder 2 <2.7 - DoS
The mp4ff_read_ctts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
CWE-834 Jun 27, 2017
CVE-2017-9256 5.5 MEDIUM EPSS 0.00
Freeware Advanced Audio Decoder 2 <2.7 - DoS
The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
CWE-834 Jun 27, 2017
CVE-2017-9255 5.5 MEDIUM EPSS 0.00
Freeware Advanced Audio Decoder 2 <2.7 - DoS
The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
CWE-834 Jun 27, 2017
CVE-2017-9254 5.5 MEDIUM EPSS 0.00
Freeware Advanced Audio Decoder 2 <2.7 - DoS
The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
CWE-834 Jun 27, 2017
CVE-2017-9253 5.5 MEDIUM EPSS 0.00
Freeware Advanced Audio Decoder 2 <2.7 - DoS
The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (large loop and CPU consumption) via a crafted mp4 file.
CWE-834 Jun 27, 2017
CVE-2017-9223 5.5 MEDIUM EPSS 0.00
Freeware Advanced Audio Decoder 2 <2.7 - DoS
The mp4ff_read_stts function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
CWE-125 Jun 27, 2017
CVE-2017-9222 5.5 MEDIUM EPSS 0.00
Freeware Advanced Audio Decoder 2 <2.7 - DoS
The mp4ff_parse_tag function in common/mp4ff/mp4meta.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted mp4 file.
CWE-835 Jun 27, 2017
CVE-2017-9221 5.5 MEDIUM EPSS 0.00
Freeware Advanced Audio Decoder 2 <2.7 - DoS
The mp4ff_read_mdhd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
CWE-125 Jun 27, 2017
CVE-2017-9220 5.5 MEDIUM EPSS 0.00
Freeware Advanced Audio Decoder 2 <2.7 - DoS
The mp4ff_read_stco function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error) via a crafted mp4 file.
CWE-119 Jun 27, 2017
CVE-2017-9219 5.5 MEDIUM EPSS 0.00
Freeware Advanced Audio Decoder 2 <2.7 - DoS
The mp4ff_read_stsc function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (memory allocation error and application crash) via a crafted mp4 file.
CWE-119 Jun 27, 2017
CVE-2017-9218 5.5 MEDIUM EPSS 0.00
Freeware Advanced Audio Decoder 2 <2.7 - DoS
The mp4ff_read_stsd function in common/mp4ff/mp4atom.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.7 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted mp4 file.
CWE-125 Jun 27, 2017
CVE-2017-9955 5.5 MEDIUM EPSS 0.00
GNU Binutils - Out-of-Bounds Read
The get_build_id function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file in which a certain size field is larger than a corresponding data field, as demonstrated by mishandling within the objdump program.
CWE-125 Jun 26, 2017
CVE-2017-9954 5.5 MEDIUM EPSS 0.00
GNU Binutils - Out-of-Bounds Read
The getvalue function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted tekhex file, as demonstrated by mishandling within the nm program.
CWE-125 Jun 26, 2017
CVE-2017-6325 6.6 MEDIUM EPSS 0.03
Symantec Messaging Gateway < 10.6.2 - Code Injection
The Symantec Messaging Gateway can encounter a file inclusion vulnerability, which is a type of vulnerability that is most commonly found to affect web applications that rely on a scripting run time. This issue is caused when an application builds a path to executable code using an attacker-controlled variable in a way that allows the attacker to control which file is executed at run time. This file inclusion vulnerability subverts how an application loads code for execution. Successful exploitation of a file inclusion vulnerability will result in remote code execution on the web server that runs the affected web application.
CWE-94 Jun 26, 2017
CVE-2015-3142 4.7 MEDIUM EPSS 0.00
Automatic Bug Reporting Tool - Info Disclosure
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.
CWE-200 Jun 26, 2017
CVE-2015-1870 5.5 MEDIUM 2 Writeups EPSS 0.00
Redhat Automatic Bug Reporting Tool < 2.1.11 - Information Disclosure
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.
CWE-200 Jun 26, 2017
CVE-2014-8127 6.5 MEDIUM EPSS 0.01
Libtiff - Out-of-Bounds Read
LibTIFF 4.0.3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted TIFF image to the (1) checkInkNamesString function in tif_dir.c in the thumbnail tool, (2) compresscontig function in tiff2bw.c in the tiff2bw tool, (3) putcontig8bitCIELab function in tif_getimage.c in the tiff2rgba tool, LZWPreDecode function in tif_lzw.c in the (4) tiff2ps or (5) tiffdither tool, (6) NeXTDecode function in tif_next.c in the tiffmedian tool, or (7) TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool.
CWE-125 Jun 26, 2017
CVE-2017-9145 6.1 MEDIUM EPSS 0.00
Tiki Wiki CMS Groupware <16.x - XSS
TikiFilter.php in Tiki Wiki CMS Groupware 12.x through 16.x does not properly validate the imgsize or lang parameter to prevent XSS.
CWE-79 Jun 26, 2017
CVE-2017-9937 6.5 MEDIUM EPSS 0.01
Libtiff < 4.0.8 - Memory Corruption
In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.
CWE-119 Jun 26, 2017
CVE-2017-9936 6.5 MEDIUM 1 PoC Analysis EPSS 0.06
Libtiff - Resource Leak
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a remote denial of service attack.
CWE-772 Jun 26, 2017