Keystone Engine is a lightweight, multi-platform assembler library designed for reverse engineering, binary analysis, and security research tooling, with a narrow but specialized product footprint. Current severity, exploitation, and exposure metrics are shown in the live statistics alongside this summary.
The number and severity of CVEs published that impact products developed by Keystone Engine over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-36405HIGH Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken. | Jul 1, 2021 | 7.8 | 23 | NO | NO |
CVE-2020-36404HIGH Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl. | Jul 1, 2021 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keystone Engine.
Media articles that mention a CVE ID that affects a product developed by Keystone Engine — matched by CVE ID, not by vendor name.