CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,864 CVEs tracked 53,333 with exploits 4,742 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,042 vendors 42,726 researchers
111,268 results Clear all
CVE-2016-9394 5.5 MEDIUM 1 Writeup EPSS 0.00
JasPer <1.900.17 - DoS
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
CWE-20 Mar 23, 2017
CVE-2016-9393 5.5 MEDIUM 1 Writeup EPSS 0.00
JasPer <1.900.17 - DoS
The jpc_pi_nextrpcl function in jpc_t2cod.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
Mar 23, 2017
CVE-2016-9392 5.5 MEDIUM 1 Writeup EPSS 0.00
JasPer <1.900.17 - DoS
The calcstepsizes function in jpc_dec.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via a crafted file.
Mar 23, 2017
CVE-2016-9390 5.5 MEDIUM 1 Writeup EPSS 0.00
JasPer <1.900.14 - DoS
The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
CWE-20 Mar 23, 2017
CVE-2016-9388 5.5 MEDIUM 1 Writeup EPSS 0.00
JasPer <1.900.14 - DoS
The ras_getcmap function in ras_dec.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a crafted image file.
CWE-617 Mar 23, 2017
CVE-2016-9266 6.5 MEDIUM EPSS 0.01
libming 0.4.7 - Memory Corruption
listmp3.c in libming 0.4.7 allows remote attackers to unspecified impact via a crafted mp3 file, which triggers an invalid left shift.
CWE-189 Mar 23, 2017
CVE-2016-9265 5.5 MEDIUM EPSS 0.00
Libming 0.4.7 - DoS
The printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp3 file.
CWE-369 Mar 23, 2017
CVE-2016-9264 5.5 MEDIUM EPSS 0.00
Libming 0.4.7 - Buffer Overflow
Buffer overflow in the printMP3Headers function in listmp3.c in Libming 0.4.7 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mp3 file.
CWE-119 Mar 23, 2017
CVE-2016-9262 5.5 MEDIUM 1 Writeup EPSS 0.00
JasPer <1.900.22 - DoS
Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.
CWE-190 Mar 23, 2017
CVE-2016-9011 5.5 MEDIUM EPSS 0.00
libwmf 0.2.8.4 - DoS
The wmf_malloc function in api.c in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (application crash) via a crafted wmf file, which triggers a memory allocation failure.
CWE-119 Mar 23, 2017
CVE-2016-8887 5.5 MEDIUM 1 Writeup EPSS 0.00
JasPer <1.900.10 - DoS
The jp2_colr_destroy function in libjasper/jp2/jp2_cod.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (NULL pointer dereference).
CWE-476 Mar 23, 2017
CVE-2016-8885 5.5 MEDIUM EPSS 0.00
JasPer <1.900.9 - DoS
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.9 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image.
CWE-476 Mar 23, 2017
CVE-2016-10058 5.5 MEDIUM EPSS 0.01
ImageMagick <6.9.6-3 - Memory Corruption
Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick before 6.9.6-3 allows remote attackers to cause a denial of service (memory consumption) via a crafted image file.
CWE-400 Mar 23, 2017
CVE-2016-10053 5.5 MEDIUM EPSS 0.00
ImageMagick <6.9.5-8 - DoS
The WriteTIFFImage function in coders/tiff.c in ImageMagick before 6.9.5-8 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted file.
CWE-369 Mar 23, 2017
CVE-2016-10047 5.5 MEDIUM EPSS 0.01
ImageMagick <6.9.4-7 - Memory Corruption
Memory leak in the NewXMLTree function in magick/xml-tree.c in ImageMagick before 6.9.4-7 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML file.
CWE-400 Mar 23, 2017
CVE-2016-10046 5.5 MEDIUM EPSS 0.00
ImageMagick <6.9.5.5 - Buffer Overflow
Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
CWE-119 Mar 23, 2017
CVE-2014-9915 5.5 MEDIUM EPSS 0.00
Imagemagick < 6.6.0-3 - Numeric Error
Off-by-one error in ImageMagick before 6.6.0-4 allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM profile.
CWE-189 Mar 23, 2017
CVE-2017-5524 4.3 MEDIUM EPSS 0.00
Plone < 4.3.12 - Format String Vulnerability
Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtain sensitive information by leveraging the Python string format method.
CWE-134 Mar 23, 2017
CVE-2016-6225 5.9 MEDIUM EPSS 0.01
Percona XtraBackup <2.3.6, 2.4.x <2.4.5 - Info Disclosure
xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information from encrypted backup files via a Chosen-Plaintext attack. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6394.
CWE-326 Mar 23, 2017
CVE-2016-10255 5.5 MEDIUM EPSS 0.01
Elfutils < 0.167 - Memory Corruption
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.
CWE-119 Mar 23, 2017