CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

339,076 CVEs tracked 53,339 with exploits 4,745 exploited in wild 1,546 CISA KEV 3,941 Nuclei templates 49,076 vendors 42,752 researchers
111,366 results Clear all
CVE-2017-7982 5.5 MEDIUM EPSS 0.00
Libimobiledevice Libplist < 1.12 - Integer Overflow
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.
CWE-190 Apr 20, 2017
CVE-2017-7938 6.6 MEDIUM 1 PoC Analysis EPSS 0.02
Mor-pah.net Dmitry Deepmagic Informat... - Memory Corruption
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long argument. An example threat model is automated execution of DMitry with hostname strings found in local log files.
CWE-119 Apr 20, 2017
CVE-2017-7282 5.5 MEDIUM EPSS 0.08
Unitrends Enterprise Backup <9.1.1 - LFI
An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the filesystem that the web server has access to, aka Local File Inclusion (LFI).
CWE-200 Apr 20, 2017
CVE-2017-7962 5.5 MEDIUM 1 Writeup EPSS 0.01
Entropymine Imageworsener - Divide By Zero
The iwgif_read_image function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
CWE-369 Apr 19, 2017
CVE-2017-7960 5.5 MEDIUM EPSS 0.01
Gnome Libcroco - Out-of-Bounds Read
The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.
CWE-125 Apr 19, 2017
CVE-2017-7849 5.5 MEDIUM EPSS 0.00
Tenable Nessus - Incorrect Permission Assignment
Nessus 6.10.x before 6.10.5 was found to be vulnerable to a local denial of service condition due to insecure permissions when running in Agent Mode.
CWE-732 Apr 19, 2017
CVE-2016-7537 6.5 MEDIUM 1 Writeup EPSS 0.02
Imagemagick < 6.9.4-7 - Out-of-Bounds Read
MagickCore/memory.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted PDB file.
CWE-125 Apr 19, 2017
CVE-2016-7533 6.5 MEDIUM 1 Writeup EPSS 0.01
Imagemagick < 6.9.4-0 - Out-of-Bounds Read
The ReadWPGImage function in coders/wpg.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WPG file.
CWE-125 Apr 19, 2017
CVE-2016-7531 6.5 MEDIUM EPSS 0.01
Imagemagick < 7.0.1-0 - Out-of-Bounds Write
MagickCore/memory.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted PDB file.
CWE-787 Apr 19, 2017
CVE-2016-7529 6.5 MEDIUM 1 Writeup EPSS 0.01
Imagemagick < 6.9.4-0 - Out-of-Bounds Read
coders/xcf.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted XCF file.
CWE-125 Apr 19, 2017
CVE-2016-7528 6.5 MEDIUM 1 Writeup EPSS 0.01
Imagemagick < 6.9.4-0 - Out-of-Bounds Read
The ReadVIFFImage function in coders/viff.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via a crafted VIFF file.
CWE-125 Apr 19, 2017
CVE-2016-7522 6.5 MEDIUM 1 Writeup EPSS 0.01
Imagemagick < 6.9.4-0 - Out-of-Bounds Read
The ReadPSDImage function in MagickCore/locale.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.
CWE-125 Apr 19, 2017
CVE-2016-7519 6.5 MEDIUM EPSS 0.01
Imagemagick < 6.9.4-0 - Out-of-Bounds Read
The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
CWE-125 Apr 19, 2017
CVE-2016-7515 6.5 MEDIUM 1 Writeup EPSS 0.01
Imagemagick < 6.9.4-0 - Out-of-Bounds Read
The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the number of pixels.
CWE-125 Apr 19, 2017
CVE-2016-5410 5.5 MEDIUM EPSS 0.00
Firewalld < 0.4.3.2 - Authentication Bypass
firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries D-Bus API method.
CWE-287 Apr 19, 2017
CVE-2014-9907 6.5 MEDIUM EPSS 0.01
Imagemagick < 6.9.4-0 - Improper Input Validation
coders/dds.c in ImageMagick allows remote attackers to cause a denial of service via a crafted DDS file.
CWE-20 Apr 19, 2017
CVE-2017-7946 5.5 MEDIUM 1 Writeup EPSS 0.00
Radare2 - Use After Free
The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted Mach0 file.
CWE-416 Apr 18, 2017
CVE-2017-7943 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
The ReadSVGImage function in svg.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
CWE-772 Apr 18, 2017
CVE-2017-7942 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
The ReadAVSImage function in avs.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
CWE-772 Apr 18, 2017
CVE-2017-7941 6.5 MEDIUM EPSS 0.01
Imagemagick - Resource Leak
The ReadSGIImage function in sgi.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
CWE-772 Apr 18, 2017