CVE & Exploit Intelligence Database

Updated 4h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,716 CVEs tracked 53,323 with exploits 4,733 exploited in wild 1,543 CISA KEV 3,939 Nuclei templates 49,017 vendors 42,676 researchers
111,142 results Clear all
CVE-2017-5665 5.5 MEDIUM EPSS 0.00
Libmp3splt - NULL Pointer Dereference
The splt_cue_export_to_file function in cue.c in libmp3splt 0.9.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
CWE-476 Mar 01, 2017
CVE-2017-5504 5.5 MEDIUM EPSS 0.00
Jasper - Out-of-Bounds Read
The jpc_undo_roi function in libjasper/jpc/jpc_dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted image.
CWE-125 Mar 01, 2017
CVE-2017-5503 5.5 MEDIUM EPSS 0.00
Jasper - Out-of-Bounds Write
The dec_clnpass function in libjasper/jpc/jpc_t1dec.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invalid memory write and crash) or possibly have unspecified other impact via a crafted image.
CWE-787 Mar 01, 2017
CVE-2017-5502 5.5 MEDIUM EPSS 0.00
Jasper - Denial of Service
libjasper/jp2/jp2_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
Mar 01, 2017
CVE-2017-5501 5.5 MEDIUM EPSS 0.00
Jasper - Integer Overflow
Integer overflow in libjasper/jpc/jpc_tsfb.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.
CWE-190 Mar 01, 2017
CVE-2017-5500 5.5 MEDIUM EPSS 0.00
Jasper - Denial of Service
libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
Mar 01, 2017
CVE-2017-5499 5.5 MEDIUM EPSS 0.00
Jasper - Integer Overflow
Integer overflow in libjasper/jpc/jpc_dec.c in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted file.
CWE-190 Mar 01, 2017
CVE-2017-5498 5.5 MEDIUM EPSS 0.00
Jasper - Denial of Service
libjasper/include/jasper/jas_math.h in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
Mar 01, 2017
CVE-2016-9826 5.5 MEDIUM EPSS 0.00
Libav - Numeric Error
libavcodec/ituh263dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
CWE-189 Mar 01, 2017
CVE-2016-9825 5.5 MEDIUM EPSS 0.00
Libav - Numeric Error
libswscale/utils.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
CWE-189 Mar 01, 2017
CVE-2016-9824 5.5 MEDIUM EPSS 0.00
Libav - Integer Overflow
Integer overflow in libswscale/x86/swscale.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
CWE-190 Mar 01, 2017
CVE-2016-9823 5.5 MEDIUM EPSS 0.00
Libav - Memory Corruption
libavcodec/x86/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
CWE-119 Mar 01, 2017
CVE-2016-9822 5.5 MEDIUM EPSS 0.00
Libav - Integer Overflow
Integer overflow in libavcodec/mpeg12dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
CWE-190 Mar 01, 2017
CVE-2016-9821 5.5 MEDIUM EPSS 0.00
Libav - Integer Overflow
Integer overflow in libavcodec/mpegvideo_parser.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
CWE-190 Mar 01, 2017
CVE-2016-9820 5.5 MEDIUM EPSS 0.00
Libav - Numeric Error
libavcodec/mpegvideo_motion.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
CWE-189 Mar 01, 2017
CVE-2016-9819 5.5 MEDIUM EPSS 0.00
Libav - Numeric Error
libavcodec/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.
CWE-189 Mar 01, 2017
CVE-2016-9559 6.5 MEDIUM 1 Writeup EPSS 0.01
Imagemagick < 6.9.6-5 - NULL Pointer Dereference
coders/tiff.c in ImageMagick before 7.0.3.7 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted image.
CWE-476 Mar 01, 2017
CVE-2016-8508 6.5 MEDIUM EPSS 0.00
Yandex Browser <17.1.1.227 - Info Disclosure
Yandex Browser for desktop before 17.1.1.227 does not show Protect (similar to Safebrowsing in Chromium) warnings in web-sites with special content-type, which could be used by remote attacker for prevention Protect warning on own malicious web-site.
CWE-254 Mar 01, 2017
CVE-2016-8507 6.5 MEDIUM EPSS 0.00
Yandex Browser for iOS <16.10.0.2357 - Info Disclosure
Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facetime-call without user's approval and obtain video and audio data from a device via a crafted web site.
CWE-200 Mar 01, 2017
CVE-2016-10095 5.5 MEDIUM EPSS 0.01
LibTIFF <4.1 - Buffer Overflow
Stack-based buffer overflow in the _TIFFVGetField function in tif_dir.c in LibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7 and 4.0.8 allows remote attackers to cause a denial of service (crash) via a crafted TIFF file.
CWE-119 Mar 01, 2017