Varaneckas maintains a narrowly scoped Java decompilation tool, JAD, which operates as a utility for code analysis and reverse engineering. The disclosed vulnerabilities center on memory-safety issues, specifically out-of-bounds write conditions that can arise during the parsing of crafted Java bytecode. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Varaneckas over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-20227CRITICAL JAD Java Decompiler 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying overly long input that | Mar 28, 2026 | 9.8 | 33 | NO | NO |
CVE-2016-20049CRITICAL JAD 1.5.8e-1kali1 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying oversized input that exceeds buffer bo | Mar 28, 2026 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Varaneckas.
Media articles that mention a CVE ID that affects a product developed by Varaneckas — matched by CVE ID, not by vendor name.