VendorsCapstone-Enginecapstoneall versions
Vulnerabilities

Capstone-Engine Capstone

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2025-68114
Capstone doesn't check vsnprintf return in SStream_concat, allows stack buffer underflow and overflow
Published 2025-12-17 · Analyzed
9.8EPSS 0.002
CVE-2017-6952
Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a kernel driver) or possibly have unspecified other impact via a large value.
Published 2017-03-16 · Modified
8.8EPSS 0.013
CVE-2025-67873
Capstone doesn't check Skipdata length, leading to cs_insn.bytes heap buffer overflow
Published 2025-12-17 · Analyzed
7.8EPSS 0.002
CVE-2026-47143
Capstone has a NULL Pointer Dereference with 3DNow! opcodes
Published 2026-07-21 · Analyzed
5.9EPSS 0.005
CVE-2016-7151
Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caused by a read memory access) in X86_insn_reg_intel in arch/X86/X86Mapping.c.
Published 2019-05-15 · Modified
5.5EPSS 0.010