Capstone Engine is a widely used disassembly and code-analysis library that, despite a narrow product footprint, is embedded in security tools, reverse-engineering frameworks, and malware-analysis platforms across the research and defense communities. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Capstone Engine over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68114CRITICAL Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat lets a malicious cs_opt_mem.vsnprintf drive SStream’s index | Dec 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2025-67873HIGH Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, Skipdata length is not bounds-checked, so a user-provided skipdata callback can make cs_disasm/cs_disasm_it | Dec 17, 2025 | 7.8 | 27 | NO | NO |
CVE-2017-6952HIGH Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a | Mar 16, 2017 | 8.8 | 27 | NO | NO |
CVE-2016-7151MEDIUM Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caused by a read memory access) in X86_insn_reg_intel in arch/X86/X86Mapping.c. | May 15, 2019 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Capstone Engine.
Media articles that mention a CVE ID that affects a product developed by Capstone Engine — matched by CVE ID, not by vendor name.