CVE & Exploit Intelligence Database

Updated 3h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,535 CVEs tracked 53,316 with exploits 4,732 exploited in wild 1,543 CISA KEV 3,936 Nuclei templates 48,971 vendors 42,621 researchers
111,009 results Clear all
CVE-2016-2198 5.5 MEDIUM EPSS 0.00
Qemu < 2.5.1.1 - NULL Pointer Dereference
QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this flaw to crash the QEMU process instance resulting in DoS.
CWE-476 Dec 29, 2016
CVE-2016-2197 5.5 MEDIUM EPSS 0.00
Qemu < 2.5.1.1 - NULL Pointer Dereference
QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw. It occurs while unmapping the Frame Information Structure (FIS) and Command List Block (CLB) entries. A privileged user inside guest could use this flaw to crash the QEMU process instance resulting in DoS.
CWE-476 Dec 29, 2016
CVE-2016-1981 5.5 MEDIUM EPSS 0.00
QEMU - DoS
QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is set outside the allocated descriptor buffer. A privileged user inside guest could use this flaw to crash the QEMU instance resulting in DoS.
CWE-835 Dec 29, 2016
CVE-2016-1922 5.5 MEDIUM EPSS 0.00
QEMU - DoS
QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference flaw. It occurs while doing I/O port write operations via hmp interface. In that, 'current_cpu' remains null, which leads to the null pointer dereference. A user or process could use this flaw to crash the QEMU instance, resulting in DoS issue.
CWE-476 Dec 29, 2016
CVE-2015-8818 5.5 MEDIUM EPSS 0.00
Qemu < 2.3.1 - Denial of Service
The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO regions, which allows local privileged guest users to cause a denial of service (guest crash) via unspecified vectors.
Dec 29, 2016
CVE-2015-8817 5.5 MEDIUM EPSS 0.00
Qemu - Out-of-Bounds Write
QEMU (aka Quick Emulator) built to use 'address_space_translate' to map an address to a MemoryRegionSection is vulnerable to an OOB r/w access issue. It could occur while doing pci_dma_read/write calls. Affects QEMU versions >= 1.6.0 and <= 2.3.1. A privileged user inside guest could use this flaw to crash the guest instance resulting in DoS.
CWE-125 Dec 29, 2016
CVE-2015-8745 5.5 MEDIUM EPSS 0.00
Qemu < 2.4.1 - Reachable Assertion
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It could occur while reading Interrupt Mask Registers (IMR). A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.
CWE-617 Dec 29, 2016
CVE-2015-8744 5.5 MEDIUM EPSS 0.00
Qemu < 2.4.1 - Improper Input Validation
QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a Layer-2 packet smaller than 22 bytes. A privileged (CAP_SYS_RAWIO) guest user could use this flaw to crash the QEMU process instance resulting in DoS.
CWE-20 Dec 29, 2016
CVE-2015-8701 6.5 MEDIUM EPSS 0.00
Qemu < 2.5.1.1 - Denial of Service
QEMU (aka Quick Emulator) built with the Rocker switch emulation support is vulnerable to an off-by-one error. It happens while processing transmit (tx) descriptors in 'tx_consume' routine, if a descriptor was to have more than allowed (ROCKER_TX_FRAGS_MAX=16) fragments. A privileged user inside guest could use this flaw to cause memory leakage on the host or crash the QEMU process instance resulting in DoS issue.
CWE-193 Dec 29, 2016
CVE-2016-9891 5.4 MEDIUM EPSS 0.00
Dotclear < 2.10.4 - XSS
Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remote authenticated users to inject arbitrary web script or HTML via the upfiletitle or media_title parameter (aka the media title).
CWE-79 Dec 29, 2016
CVE-2016-7463 5.4 MEDIUM EPSS 0.00
Vmware Esxi - XSS
Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted VM.
CWE-79 Dec 29, 2016
CVE-2016-7458 5.8 MEDIUM EPSS 0.00
Vmware Vsphere Client - XXE
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CWE-611 Dec 29, 2016
CVE-2016-7087 5.3 MEDIUM EPSS 0.03
Vmware Horizon View - Path Traversal
Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, and 7.x before 7.0.1 allows remote attackers to obtain sensitive information via unspecified vectors.
CWE-22 Dec 29, 2016
CVE-2016-5334 5.3 MEDIUM EPSS 0.00
Vmware Identity Manager < 2.7.1 - Exposure to Wrong Actor
VMware Identity Manager 2.x before 2.7.1 and vRealize Automation 7.x before 7.2.0 allow remote attackers to read /SAAS/WEB-INF and /SAAS/META-INF files via unspecified vectors.
CWE-668 Dec 29, 2016
CVE-2016-5329 5.5 MEDIUM EPSS 0.00
Vmware Fusion - Information Disclosure
VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.
CWE-200 Dec 29, 2016
CVE-2016-5328 5.5 MEDIUM EPSS 0.00
Vmware Tools < 10.0.8 - Information Disclosure
VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and bypass the kASLR protection mechanism via unspecified vectors.
CWE-254 Dec 29, 2016
CVE-2016-9756 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux Kernel < 4.8.11 - Information Disclosure
arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
CWE-200 Dec 28, 2016
CVE-2016-9685 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux Kernel < 4.5.0 - Denial of Service
Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kernel before 4.5.1 allow local users to cause a denial of service (memory consumption) via crafted XFS filesystem operations.
CWE-400 Dec 28, 2016
CVE-2016-9588 5.5 MEDIUM 1 Writeup EPSS 0.00
Linux Kernel < 4.9 - Denial of Service
arch/x86/kvm/vmx.c in the Linux kernel through 4.9 mismanages the #BP and #OF exceptions, which allows guest OS users to cause a denial of service (guest OS crash) by declining to handle an exception thrown by an L2 guest.
CWE-388 Dec 28, 2016
CVE-2016-6213 4.7 MEDIUM EPSS 0.00
Linux kernel <4.9 - DoS
fs/namespace.c in the Linux kernel before 4.9 does not restrict how many mounts may exist in a mount namespace, which allows local users to cause a denial of service (memory consumption and deadlock) via MS_BIND mount system calls, as demonstrated by a loop that triggers exponential growth in the number of mounts.
CWE-400 Dec 28, 2016