CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,716 CVEs tracked 53,323 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,939 Nuclei templates 49,017 vendors 42,676 researchers
111,142 results Clear all
CVE-2017-6387 5.5 MEDIUM 1 Writeup EPSS 0.00
Radare2 - Out-of-Bounds Read
The dex_loadcode function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted DEX file.
CWE-125 Mar 02, 2017
CVE-2016-10228 5.9 MEDIUM EPSS 0.00
GNU Glibc < 2.25 - Improper Input Validation
The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.
CWE-20 Mar 02, 2017
CVE-2016-8232 6.1 MEDIUM EPSS 0.00
Lenovo IBM BladeCenter - XSS
Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM's IP address to send a crafted URL that could inject a malicious script to access a user's AMM data such as cookies or other session information.
CWE-79 Mar 01, 2017
CVE-2016-5932 5.4 MEDIUM EPSS 0.00
IBM Connections <5.6 - XSS
IBM Connections 4.0, 4.5, 5.0, and 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1998294.
CWE-79 Mar 01, 2017
CVE-2017-6353 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux Kernel < 4.10 - Double Free
net/sctp/socket.c in the Linux kernel through 4.10.1 does not properly restrict association peel-off operations during certain wait states, which allows local users to cause a denial of service (invalid unlock and double free) via a multithreaded application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-5986.
CWE-415 Mar 01, 2017
CVE-2017-6348 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux Kernel < 4.9.12 - Denial of Service
The hashbin_delete function in net/irda/irqueue.c in the Linux kernel before 4.9.13 improperly manages lock dropping, which allows local users to cause a denial of service (deadlock) via crafted operations on IrDA devices.
Mar 01, 2017
CVE-2016-9830 5.5 MEDIUM EPSS 0.01
Graphicsmagick - Improper Input Validation
The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service (crash) via large dimensions in a jpeg image.
CWE-20 Mar 01, 2017
CVE-2017-5981 5.5 MEDIUM EPSS 0.00
Gdraheim Zziplib - Reachable Assertion
seeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (assertion failure and crash) via a crafted ZIP file.
CWE-617 Mar 01, 2017
CVE-2017-5980 5.5 MEDIUM EPSS 0.00
Gdraheim Zziplib - NULL Pointer Dereference
The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file.
CWE-476 Mar 01, 2017
CVE-2017-5979 5.5 MEDIUM EPSS 0.00
Gdraheim Zziplib - NULL Pointer Dereference
The prescan_entry function in fseeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file.
CWE-476 Mar 01, 2017
CVE-2017-5978 5.5 MEDIUM EPSS 0.00
Gdraheim Zziplib - Out-of-Bounds Read
The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ZIP file.
CWE-125 Mar 01, 2017
CVE-2017-5977 5.5 MEDIUM EPSS 0.00
Gdraheim Zziplib - Out-of-Bounds Read
The zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted ZIP file.
CWE-125 Mar 01, 2017
CVE-2017-5976 5.5 MEDIUM EPSS 0.01
Gdraheim Zziplib - Out-of-Bounds Write
Heap-based buffer overflow in the zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.
CWE-787 Mar 01, 2017
CVE-2017-5975 5.5 MEDIUM EPSS 0.01
Gdraheim Zziplib - Out-of-Bounds Write
Heap-based buffer overflow in the __zzip_get64 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.
CWE-787 Mar 01, 2017
CVE-2017-5974 5.5 MEDIUM EPSS 0.01
Gdraheim Zziplib - Memory Corruption
Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file.
CWE-119 Mar 01, 2017
CVE-2017-5855 5.5 MEDIUM EPSS 0.00
Podofo - NULL Pointer Dereference
The PoDoFo::PdfParser::ReadXRefSubsection function in PdfParser.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
CWE-476 Mar 01, 2017
CVE-2017-5854 5.5 MEDIUM EPSS 0.01
Podofo - NULL Pointer Dereference
base/PdfOutputStream.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
CWE-476 Mar 01, 2017
CVE-2017-5852 5.5 MEDIUM EPSS 0.00
Podofo - Infinite Loop
The PoDoFo::PdfPage::GetInheritedKeyFromObject function in base/PdfVariant.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted file.
CWE-835 Mar 01, 2017
CVE-2017-5851 5.5 MEDIUM EPSS 0.00
Mp3splt - NULL Pointer Dereference
The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. NOTE: this typically has no risk; this crash of this command-line program has no further consequences for availability.
CWE-476 Mar 01, 2017
CVE-2017-5666 5.5 MEDIUM EPSS 0.00
Mp3splt - Use After Free
The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (invalid free and crash) via a crafted file.
CWE-416 Mar 01, 2017