Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Icoutils Project

First CVE: Feb 16, 2017Active for: 9 yearsTotal CVEs: 7

Icoutils is a utility suite for manipulating Microsoft Windows icon and cursor files, occupying a narrow but strategically embedded niche in image-processing toolchains and file-handling pipelines across multiple platforms. The vulnerability profile recurs through memory-safety weakness classes including buffer boundary violations, integer overflow conditions, and out-of-bounds reads that are typical of C-based parsers handling binary file formats. Defenders should monitor this vendor's releases when icon or cursor file processing is exposed to untrusted input; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
3.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Icoutils Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 16, 2017
9 years ago
Most Recent CVE
Nov 4, 2019
2,454 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-5208HIGH
Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers
Aug 22, 20178.829NONO
CVE-2017-5333HIGH
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash
Nov 4, 20197.826NONO
CVE-2017-5332HIGH
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process
Nov 4, 20197.826NONO
CVE-2017-5331HIGH
Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitra
Nov 4, 20197.826NONO
CVE-2017-6011MEDIUM
An issue was discovered in icoutils 0.31.1. An out-of-bounds read leading to a buffer overflow was observed in the "simple_vec" function in the "extract.c" source file. This affect
Feb 16, 20175.520NONO
CVE-2017-6009MEDIUM
An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "l
Feb 16, 20175.520NONO
CVE-2017-6010MEDIUM
An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extract_icons" function in the "extract.c" source file. This issue can be triggered by processing
Feb 16, 20175.519NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
43%
57%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (85.7%)
Network1 (14.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (14.3%)
Unknown0 (0.0%)
Required6 (85.7%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None6 (85.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Icoutils Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Icoutils Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Icoutils Project's Products

View all 2 CNAs →

Top CWEs