CVE & Exploit Intelligence Database

Updated 1h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,831 CVEs tracked 53,332 with exploits 4,739 exploited in wild 1,545 CISA KEV 3,939 Nuclei templates 49,039 vendors 42,720 researchers
111,250 results Clear all
CVE-2017-6440 5.0 MEDIUM EPSS 0.00
Libplist - Integer Overflow
The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.
CWE-190 Mar 15, 2017
CVE-2017-6439 5.0 MEDIUM 1 Writeup EPSS 0.00
Libplist - Out-of-Bounds Write
Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file.
CWE-787 Mar 15, 2017
CVE-2017-6437 5.0 MEDIUM EPSS 0.00
Libplist - Out-of-Bounds Read
The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.
CWE-125 Mar 15, 2017
CVE-2017-6436 5.0 MEDIUM 1 Writeup EPSS 0.00
Libplist - Memory Corruption
The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.
CWE-119 Mar 15, 2017
CVE-2017-6435 5.0 MEDIUM 1 Writeup EPSS 0.00
Libplist - Memory Corruption
The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory corruption) via a crafted plist file.
CWE-119 Mar 15, 2017
CVE-2017-6414 6.5 MEDIUM EPSS 0.00
Libcacard < 2.5.3 - Resource Leak
Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object.
CWE-772 Mar 15, 2017
CVE-2017-6386 6.5 MEDIUM EPSS 0.00
Virglrenderer < 0.8.0 - Resource Leak
Memory leak in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_OBJECT_VERTEX_ELEMENTS commands.
CWE-772 Mar 15, 2017
CVE-2017-6317 6.5 MEDIUM EPSS 0.00
Virglrenderer < 0.5.0 - Resource Leak
Memory leak in the add_shader_program function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via vectors involving the sprog variable.
CWE-772 Mar 15, 2017
CVE-2017-6210 6.5 MEDIUM EPSS 0.00
Virglrenderer < 0.5.0 - NULL Pointer Dereference
The vrend_decode_reset function in vrend_decode.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (NULL pointer dereference and QEMU process crash) by destroying context 0 (zero).
CWE-476 Mar 15, 2017
CVE-2017-6209 6.5 MEDIUM EPSS 0.00
Virglrenderer < 0.5.0 - Memory Corruption
Stack-based buffer overflow in the parse_identifier function in tgsi_text.c in the TGSI auxiliary module in the Gallium driver in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors related to parsing properties.
CWE-119 Mar 15, 2017
CVE-2017-5994 5.5 MEDIUM EPSS 0.00
Virglrenderer < 0.5.0 - Memory Corruption
Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and crash) via the num_elements parameter.
CWE-119 Mar 15, 2017
CVE-2017-5993 6.5 MEDIUM EPSS 0.00
Virglrenderer < 0.5.0 - Resource Leak
Memory leak in the vrend_renderer_init_blit_ctx function in vrend_blitter.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_CCMD_BLIT commands.
CWE-772 Mar 15, 2017
CVE-2017-5938 6.1 MEDIUM 1 Writeup EPSS 0.01
Debian Linux < 1.1.25 - XSS
Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.0.14 and 1.1.x before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.
CWE-79 Mar 15, 2017
CVE-2017-5584 5.4 MEDIUM EPSS 0.00
Paloaltonetworks Pan-os - XSS
Cross-site scripting (XSS) vulnerability in the Management Web Interface in Palo Alto Networks PAN-OS 5.1, 6.x before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
CWE-79 Mar 15, 2017
CVE-2017-5583 6.5 MEDIUM EPSS 0.01
Paloaltonetworks Pan-os < 6.1.15 - Information Disclosure
The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.16, 7.0.x before 7.0.13, and 7.1.x before 7.1.8 allows remote authenticated users to read arbitrary files via unspecified vectors.
CWE-200 Mar 15, 2017
CVE-2016-6906 5.5 MEDIUM EPSS 0.00
Libgd < 2.2.3 - Out-of-Bounds Read
The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file, related to the decompression buffer.
CWE-125 Mar 15, 2017
CVE-2017-6909 6.1 MEDIUM EPSS 0.00
Shimmie <= 2.5.1 - XSS
An issue was discovered in Shimmie <= 2.5.1. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "shimmie2-master/ext/chatbox/history/index.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Mar 15, 2017
CVE-2017-6908 6.1 MEDIUM 1 Writeup EPSS 0.00
Concrete5 <= 5.6.3.4 - XSS
An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (fID) passed to the "concrete5-legacy-master/web/concrete/tools/files/selector_data.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Mar 15, 2017
CVE-2017-6907 6.1 MEDIUM EPSS 0.00
Open.GL <2017-03-13 - XSS
An issue was discovered in Open.GL before 2017-03-13. The vulnerability exists due to insufficient filtration of user-supplied data (content) passed to the "Open.GL-master/index.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Mar 15, 2017
CVE-2017-6906 6.1 MEDIUM EPSS 0.00
SiberianCMS <4.10.0 - XSS
An issue was discovered in SiberianCMS before 4.10.0. The vulnerability exists due to insufficient filtration of user-supplied data (log) passed to the "SiberianCMS-master/errors/500.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
CWE-79 Mar 15, 2017