Icoutils is a utility suite for manipulating Microsoft Windows icon and cursor files, occupying a narrow but strategically embedded niche in image-processing toolchains and file-handling pipelines across multiple platforms. The vulnerability profile recurs through memory-safety weakness classes including buffer boundary violations, integer overflow conditions, and out-of-bounds reads that are typical of C-based parsers handling binary file formats. Defenders should monitor this vendor's releases when icon or cursor file processing is exposed to untrusted input; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Icoutils Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5208HIGH Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers | Aug 22, 2017 | 8.8 | 29 | NO | NO |
CVE-2017-5333HIGH Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash | Nov 4, 2019 | 7.8 | 26 | NO | NO |
CVE-2017-5332HIGH The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process | Nov 4, 2019 | 7.8 | 26 | NO | NO |
CVE-2017-5331HIGH Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitra | Nov 4, 2019 | 7.8 | 26 | NO | NO |
CVE-2017-6011MEDIUM An issue was discovered in icoutils 0.31.1. An out-of-bounds read leading to a buffer overflow was observed in the "simple_vec" function in the "extract.c" source file. This affect | Feb 16, 2017 | 5.5 | 20 | NO | NO |
CVE-2017-6009MEDIUM An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "l | Feb 16, 2017 | 5.5 | 20 | NO | NO |
CVE-2017-6010MEDIUM An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extract_icons" function in the "extract.c" source file. This issue can be triggered by processing | Feb 16, 2017 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Icoutils Project.
Media articles that mention a CVE ID that affects a product developed by Icoutils Project — matched by CVE ID, not by vendor name.