CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,831 CVEs tracked 53,332 with exploits 4,739 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,039 vendors 42,720 researchers
111,250 results Clear all
CVE-2017-5579 6.5 MEDIUM EPSS 0.00
Qemu < 2.8.1.1 - Memory Leak
Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
CWE-401 Mar 15, 2017
CVE-2017-5578 6.5 MEDIUM EPSS 0.00
Qemu < 2.8.1.1 - Memory Leak
Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
CWE-401 Mar 15, 2017
CVE-2017-5552 6.5 MEDIUM EPSS 0.00
Qemu < 2.8.1.1 - Memory Leak
Memory leak in the virgl_resource_attach_backing function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.
CWE-401 Mar 15, 2017
CVE-2017-5537 5.3 MEDIUM 1 Writeup EPSS 0.01
Weblate < 2.10 - Information Disclosure
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
CWE-200 Mar 15, 2017
CVE-2017-5526 6.5 MEDIUM EPSS 0.00
Qemu < 2.8.1.1 - Memory Leak
Memory leak in hw/audio/es1370.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
CWE-401 Mar 15, 2017
CVE-2017-5525 6.5 MEDIUM EPSS 0.00
Qemu < 2.8.1.1 - Memory Leak
Memory leak in hw/audio/ac97.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
CWE-401 Mar 15, 2017
CVE-2016-10167 5.5 MEDIUM EPSS 0.01
Libgd < 2.2.3 - Improper Input Validation
The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
CWE-20 Mar 15, 2017
CVE-2016-10163 6.5 MEDIUM EPSS 0.00
virglrenderer <0.6.0 - DoS
Memory leak in the vrend_renderer_context_create_internal function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) by repeatedly creating a decode context.
CWE-399 Mar 15, 2017
CVE-2016-10155 6.0 MEDIUM EPSS 0.00
QEMU - DoS
Memory leak in hw/watchdog/wdt_i6300esb.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.
CWE-401 Mar 15, 2017
CVE-2017-6851 5.5 MEDIUM EPSS 0.00
JasPer 2.0.10 - DoS
The jas_matrix_bindsub function in jas_seq.c in JasPer 2.0.10 allows remote attackers to cause a denial of service (invalid read) via a crafted image.
CWE-125 Mar 15, 2017
CVE-2017-6850 5.5 MEDIUM 1 Writeup EPSS 0.00
JasPer <2.0.13 - DoS
The jp2_cdef_destroy function in jp2_cod.c in JasPer before 2.0.13 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image.
CWE-476 Mar 15, 2017
CVE-2017-6849 5.5 MEDIUM EPSS 0.00
PoDoFo <0.9.4 - DoS
The PoDoFo::PdfColorGray::~PdfColorGray function in PdfColor.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Mar 15, 2017
CVE-2017-6848 5.5 MEDIUM EPSS 0.00
PoDoFo <0.9.5 - DoS
The PoDoFo::PdfXObject::PdfXObject function in PdfXObject.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Mar 15, 2017
CVE-2017-6847 5.5 MEDIUM EPSS 0.00
PoDoFo <0.9.4 - DoS
The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Mar 15, 2017
CVE-2017-6846 5.5 MEDIUM EPSS 0.00
PoDoFo 0.9.4 - DoS
The GraphicsStack::TGraphicsStackElement::SetNonStrokingColorSpace function in graphicsstack.h in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Mar 15, 2017
CVE-2017-6845 5.5 MEDIUM EPSS 0.00
PoDoFo <0.9.4 - DoS
The PoDoFo::PdfColor::operator function in PdfColor.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Mar 15, 2017
CVE-2017-6842 5.5 MEDIUM EPSS 0.00
PoDoFo 0.9.5 - DoS
The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Mar 15, 2017
CVE-2017-6841 5.5 MEDIUM EPSS 0.00
PoDoFo 0.9.5 - DoS
The GraphicsStack::TGraphicsStackElement::~TGraphicsStackElement function in graphicsstack.h in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Mar 15, 2017
CVE-2017-6840 5.5 MEDIUM EPSS 0.00
PoDoFo 0.9.5 - DoS
The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (invalid read) via a crafted file.
CWE-125 Mar 15, 2017
CVE-2017-6505 6.5 MEDIUM EPSS 0.00
Qemu < 2.8.1.1 - Infinite Loop
The ohci_service_ed_list function in hw/usb/hcd-ohci.c in QEMU (aka Quick Emulator) before 2.9.0 allows local guest OS users to cause a denial of service (infinite loop) via vectors involving the number of link endpoint list descriptors, a different vulnerability than CVE-2017-9330.
CWE-835 Mar 15, 2017