Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Virustotal

First CVE: Apr 3, 2017Active for: 9 yearsTotal CVEs: 21
44.6
VTI Score
High

Virustotal operates the widely used malware analysis and file-reputation platform that underpins threat intelligence for security teams across the industry, alongside its companion YARA pattern-matching engine for malware detection and forensics. Despite a narrow product portfolio, both components sit deep in security infrastructure and are heavily integrated into detection workflows, giving vulnerabilities in these tools outsized operational significance. The recurring exposure centers on memory-safety weaknesses—out-of-bounds reads and writes, use-after-free conditions, buffer overflows, and uncontrolled recursion—that arise from the parser-intensive demands of processing untrusted malware samples and pattern matching at scale. Defenders should treat updates to these tools as priority items given their role in threat analysis pipelines, even though the vendor's vulnerability profile itself skews toward lower severity bands. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
1.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Virustotal over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2017
9 years ago
Most Recent CVE
Aug 28, 2023
1,061 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3402CRITICAL
An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker to either cause denial of service or infor
May 14, 20219.128NONO
CVE-2019-19648HIGH
In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bound
Dec 9, 20197.826NONO
CVE-2017-9438HIGH
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandl
Jun 5, 20177.526NONO
CVE-2017-8294HIGH
libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishand
Apr 27, 20177.526NONO
CVE-2017-9304HIGH
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit fu
May 31, 20177.525NONO
CVE-2017-8929HIGH
The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule.
May 14, 20177.525NONO
CVE-2016-10210HIGH
libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted rule that is mishandled in the yy_
Apr 3, 20177.525NONO
CVE-2023-40857HIGH
Buffer Overflow vulnerability in VirusTotal yara v.4.3.2 allows a remote attacker to execute arbtirary code via the yr_execute_cod function in the exe.c component.
Aug 28, 20238.824NONO
CVE-2017-9465HIGH
The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from pr
Jun 6, 20177.124NONO
CVE-2016-10211HIGH
libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_parser_l
Apr 3, 20177.524NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
29%
67%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local11 (52.4%)
Network10 (47.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (42.9%)
Unknown0 (0.0%)
Required12 (57.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None21 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Virustotal.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Virustotal — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Virustotal's Products

View all 3 CNAs →

Top CWEs