CVE & Exploit Intelligence Database

Updated 5h ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

338,223 CVEs tracked 53,271 with exploits 4,730 exploited in wild 1,542 CISA KEV 3,929 Nuclei templates 37,826 vendors 42,547 researchers
268 results Clear all
CVE-2017-16829 7.8 HIGH EPSS 0.01
GNU Binutils 2.29.1 - DoS
The _bfd_elf_parse_gnu_properties function in elf-properties.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not prevent negative pointers, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a crafted ELF file.
CWE-125 Nov 15, 2017
CVE-2017-16828 7.8 HIGH EPSS 0.00
GNU Binutils 2.29.1 - DoS
The display_debug_frames function in dwarf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (integer overflow and heap-based buffer over-read, and application crash) or possibly have unspecified other impact via a crafted ELF file, related to print_debug_frame.
CWE-190 Nov 15, 2017
CVE-2017-16827 7.8 HIGH EPSS 0.00
GNU Binutils 2.29.1 - DoS
The aout_get_external_symbols function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (slurp_symtab invalid free and application crash) or possibly have unspecified other impact via a crafted ELF file.
CWE-119 Nov 15, 2017
CVE-2017-16826 7.8 HIGH EPSS 0.00
GNU Binutils 2.29.1 - DoS
The coff_slurp_line_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted PE file.
CWE-119 Nov 15, 2017
CVE-2017-15996 7.8 HIGH EPSS 0.00
GNU Binutils - Memory Corruption
elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a denial of service (excessive memory allocation) or possibly have unspecified other impact via a crafted ELF file that triggers a "buffer overflow on fuzzed archive header," related to an uninitialized variable, an improper conditional jump, and the get_archive_member_name, process_archive_index_and_symbols, and setup_archive functions.
CWE-119 Oct 29, 2017
CVE-2017-15939 5.5 MEDIUM EPSS 0.00
GNU Binutils - NULL Pointer Dereference
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename. NOTE: this issue is caused by an incomplete fix for CVE-2017-15023.
CWE-476 Oct 27, 2017
CVE-2017-15938 7.5 HIGH EPSS 0.01
GNU Binutils - Memory Corruption
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, miscalculates DW_FORM_ref_addr die refs in the case of a relocatable object file, which allows remote attackers to cause a denial of service (find_abstract_instance_name invalid memory read, segmentation fault, and application crash).
CWE-119 Oct 27, 2017
CVE-2017-15225 5.5 MEDIUM EPSS 0.00
GNU Binutils - Resource Leak
_bfd_dwarf2_cleanup_debug_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory leak) via a crafted ELF file.
CWE-772 Oct 10, 2017
CVE-2017-15025 5.5 MEDIUM EPSS 0.00
GNU Binutils - Divide By Zero
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted ELF file.
CWE-369 Oct 05, 2017
CVE-2017-15024 5.5 MEDIUM EPSS 0.00
GNU Binutils - Infinite Loop
find_abstract_instance_name in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
CWE-835 Oct 05, 2017
CVE-2017-15023 5.5 MEDIUM EPSS 0.00
GNU Binutils - NULL Pointer Dereference
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.
CWE-476 Oct 05, 2017
CVE-2017-15022 5.5 MEDIUM EPSS 0.00
GNU Binutils - NULL Pointer Dereference
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the DW_AT_name data type, which allows remote attackers to cause a denial of service (bfd_hash_hash NULL pointer dereference, or out-of-bounds access, and application crash) via a crafted ELF file, related to scan_unit_for_symbols and parse_comp_unit.
CWE-476 Oct 05, 2017
CVE-2017-15021 5.5 MEDIUM EPSS 0.00
GNU Binutils - Out-of-Bounds Read
bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to bfd_getl32.
CWE-125 Oct 05, 2017
CVE-2017-15020 7.8 HIGH EPSS 0.00
GNU Binutils - Out-of-Bounds Read
dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles pointers, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file, related to parse_die and parse_line_table, as demonstrated by a parse_die heap-based buffer over-read.
CWE-125 Oct 05, 2017
CVE-2017-14974 5.5 MEDIUM EPSS 0.00
GNU Binutils - NULL Pointer Dereference
The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandle the failure of a certain canonicalization step, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to elf32-i386.c and elf64-x86-64.c.
CWE-476 Oct 02, 2017
CVE-2017-14940 5.5 MEDIUM EPSS 0.00
GNU Binutils - NULL Pointer Dereference
scan_unit_for_symbols in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file.
CWE-476 Sep 30, 2017
CVE-2017-14939 5.5 MEDIUM 1 PoC Analysis EPSS 0.03
GNU Binutils - Out-of-Bounds Read
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calculation, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to read_1_byte.
CWE-125 Sep 30, 2017
CVE-2017-14938 5.5 MEDIUM EPSS 0.00
GNU Binutils - Resource Allocation Without Limits
_bfd_elf_slurp_version_tables in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file.
CWE-770 Sep 30, 2017
CVE-2017-14934 5.5 MEDIUM EPSS 0.00
GNU Binutils - Denial of Service
process_debug_info in dwarf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file that contains a negative size value in a CU structure.
CWE-131 Sep 30, 2017
CVE-2017-14933 5.5 MEDIUM EPSS 0.00
GNU Binutils 2.29 - DoS
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file.
CWE-835 Sep 30, 2017