Unicorn Engine is a lightweight CPU emulation framework used in reverse engineering, malware analysis, and vulnerability research tooling; despite a narrow product scope, it occupies a specialized but significant role in security research infrastructure. The vendor's disclosures reflect the emulation layer's exposure to parsing and state-management complexity across supported architectures. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unicorn Engine over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29694HIGH Unicorn Engine v2.0.0-rc7 and below was discovered to contain a NULL pointer dereference via qemu_ram_free. | Jun 2, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-29692HIGH Unicorn Engine v1.0.3 was discovered to contain a use-after-free vulnerability via the hook function. | Jun 2, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-44078HIGH An issue was discovered in split_region in uc.c in Unicorn Engine before 2.0.0-rc5. It allows local attackers to escape the sandbox. An attacker must first obtain the ability to ex | Dec 26, 2021 | 8.1 | 25 | NO | NO |
CVE-2022-29695HIGH Unicorn Engine v2.0.0-rc7 contains memory leaks caused by an incomplete unicorn engine initialization. | Jun 2, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-36979MEDIUM Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb). | Jul 20, 2021 | 5.5 | 21 | NO | NO |
CVE-2022-29693HIGH Unicorn Engine v2.0.0-rc7 and below was discovered to contain a memory leak via the function uc_close at /my/unicorn/uc.c. | Jun 2, 2022 | 7.5 | 19 | NO | NO |
CVE-2020-36431MEDIUM Unicorn Engine 1.0.2 has an out-of-bounds write in helper_wfe_arm. | Jul 20, 2021 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unicorn Engine.
Media articles that mention a CVE ID that affects a product developed by Unicorn Engine — matched by CVE ID, not by vendor name.