Virustotal operates the widely used malware analysis and file-reputation platform that underpins threat intelligence for security teams across the industry, alongside its companion YARA pattern-matching engine for malware detection and forensics. Despite a narrow product portfolio, both components sit deep in security infrastructure and are heavily integrated into detection workflows, giving vulnerabilities in these tools outsized operational significance. The recurring exposure centers on memory-safety weaknesses—out-of-bounds reads and writes, use-after-free conditions, buffer overflows, and uncontrolled recursion—that arise from the parser-intensive demands of processing untrusted malware samples and pattern matching at scale. Defenders should treat updates to these tools as priority items given their role in threat analysis pipelines, even though the vendor's vulnerability profile itself skews toward lower severity bands. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Virustotal over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3402CRITICAL An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker to either cause denial of service or infor | May 14, 2021 | 9.1 | 28 | NO | NO |
CVE-2019-19648HIGH In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bound | Dec 9, 2019 | 7.8 | 26 | NO | NO |
CVE-2017-9438HIGH libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandl | Jun 5, 2017 | 7.5 | 26 | NO | NO |
CVE-2017-8294HIGH libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishand | Apr 27, 2017 | 7.5 | 26 | NO | NO |
CVE-2017-9304HIGH libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit fu | May 31, 2017 | 7.5 | 25 | NO | NO |
CVE-2017-8929HIGH The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule. | May 14, 2017 | 7.5 | 25 | NO | NO |
CVE-2016-10210HIGH libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted rule that is mishandled in the yy_ | Apr 3, 2017 | 7.5 | 25 | NO | NO |
CVE-2023-40857HIGH Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component. | Aug 28, 2023 | 8.8 | 24 | NO | NO |
CVE-2017-9465HIGH The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from pr | Jun 6, 2017 | 7.1 | 24 | NO | NO |
CVE-2016-10211HIGH libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_parser_l | Apr 3, 2017 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Virustotal.
Media articles that mention a CVE ID that affects a product developed by Virustotal — matched by CVE ID, not by vendor name.