CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
110,849 results Clear all
CVE-2012-0248 5.5 MEDIUM EPSS 0.00
Imagemagick < 6.7.5-7 - Infinite Loop
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
CWE-835 Jun 05, 2012
CVE-2011-4081 5.5 MEDIUM EPSS 0.00
Linux kernel <3.1 - DoS
crypto/ghash-generic.c in the Linux kernel before 3.1 allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact by triggering a failed or missing ghash_setkey function call, followed by a (1) ghash_update function call or (2) ghash_final function call, as demonstrated by a write operation on an AF_ALG socket.
CWE-476 May 24, 2012
CVE-2011-3363 6.5 MEDIUM EPSS 0.00
Linux Kernel < 2.6.39 - Improper Input Validation
The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.
CWE-20 May 24, 2012
CVE-2011-3353 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.1 - Buffer Overflow
Buffer overflow in the fuse_notify_inval_entry function in fs/fuse/dev.c in the Linux kernel before 3.1 allows local users to cause a denial of service (BUG_ON and system crash) by leveraging the ability to mount a FUSE filesystem.
CWE-120 May 24, 2012
CVE-2011-2918 5.5 MEDIUM 1 PoC Analysis EPSS 0.00
Linux Kernel < 3.1 - Denial of Service
The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK events, which allows local users to cause a denial of service (system hang) via a crafted application.
CWE-400 May 24, 2012
CVE-2011-2906 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.1 - Denial of Service
Integer signedness error in the pmcraid_ioctl_passthrough function in drivers/scsi/pmcraid.c in the Linux kernel before 3.1 might allow local users to cause a denial of service (memory consumption or memory corruption) via a negative size value in an ioctl call. NOTE: this may be a vulnerability only in unusual environments that provide a privileged program for obtaining the required file descriptor.
CWE-400 May 24, 2012
CVE-2011-2898 5.5 MEDIUM EPSS 0.00
Linux Kernel < 2.6.39.3 - Information Disclosure
net/packet/af_packet.c in the Linux kernel before 2.6.39.3 does not properly restrict user-space access to certain packet data structures associated with VLAN Tag Control Information, which allows local users to obtain potentially sensitive information via a crafted application.
CWE-200 May 24, 2012
CVE-2011-2707 6.0 MEDIUM EPSS 0.00
Linux Kernel < 3.1 - Information Disclosure
The ptrace_setxregs function in arch/xtensa/kernel/ptrace.c in the Linux kernel before 3.1 does not validate user-space pointers, which allows local users to obtain sensitive information from kernel memory locations via a crafted PTRACE_SETXTREGS request.
CWE-200 May 24, 2012
CVE-2012-1146 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.2.10 - NULL Pointer Dereference
The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold events.
CWE-476 May 17, 2012
CVE-2012-1090 5.5 MEDIUM EPSS 0.00
Linux kernel <3.2.10 - DoS
The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.
CWE-20 May 17, 2012
CVE-2012-0879 5.5 MEDIUM EPSS 0.00
Linux kernel <2.6.33 - DoS
The I/O implementation for block devices in the Linux kernel before 2.6.33 does not properly handle the CLONE_IO feature, which allows local users to cause a denial of service (I/O instability) by starting multiple processes that share an I/O context.
CWE-400 May 17, 2012
CVE-2012-0058 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.2.2 - Denial of Service
The kiocb_batch_free function in fs/aio.c in the Linux kernel before 3.2.2 allows local users to cause a denial of service (OOPS) via vectors that trigger incorrect iocb management.
CWE-400 May 17, 2012
CVE-2012-0038 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.1.9 - Integer Overflow
Integer overflow in the xfs_acl_from_disk function in fs/xfs/xfs_acl.c in the Linux kernel before 3.1.9 allows local users to cause a denial of service (panic) via a filesystem with a malformed ACL, leading to a heap-based buffer overflow.
CWE-190 May 17, 2012
CVE-2011-4621 5.5 MEDIUM EPSS 0.00
Linux Kernel < 2.6.37 - Infinite Loop
The Linux kernel before 2.6.37 does not properly implement a certain clock-update optimization, which allows local users to cause a denial of service (system hang) via an application that executes code in a loop.
CWE-835 May 17, 2012
CVE-2011-4594 5.5 MEDIUM EPSS 0.00
Linux Kernel < 3.1 - NULL Pointer Dereference
The __sys_sendmsg function in net/socket.c in the Linux kernel before 3.1 allows local users to cause a denial of service (system crash) via crafted use of the sendmmsg system call, leading to an incorrect pointer dereference.
CWE-476 May 17, 2012
CVE-2011-4112 5.5 MEDIUM EPSS 0.00
Linux kernel <3.1 - DoS
The net subsystem in the Linux kernel before 3.1 does not properly restrict use of the IFF_TX_SKB_SHARING flag, which allows local users to cause a denial of service (panic) by leveraging the CAP_NET_ADMIN capability to access /proc/net/pktgen/pgctrl, and then using the pktgen package in conjunction with a bridge device for a VLAN interface.
May 17, 2012
CVE-2011-4097 5.5 MEDIUM EPSS 0.00
Linux Kernel <3.1.8 - DoS
Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory.
CWE-190 May 17, 2012
CVE-2011-3637 5.5 MEDIUM EPSS 0.00
Linux kernel <2.6.39 - DoS
The m_stop function in fs/proc/task_mmu.c in the Linux kernel before 2.6.39 allows local users to cause a denial of service (OOPS) via vectors that trigger an m_start error.
CWE-476 May 17, 2012
CVE-2012-1695 6.8 MEDIUM EPSS 0.01
Oracle JRockit - Info Disclosure
Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and earlier, and JDK/JRE 5 and 6 27.7.1 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
May 03, 2012
CVE-2012-0767 6.1 MEDIUM KEV EPSS 0.16
Adobe Flash Player <10.3.183.15,11.x<11.1.102.62 - XSS
Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)," as exploited in the wild in February 2012.
CWE-79 Feb 16, 2012