2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-15835 | — | — | 0.2% | Dec 7, 2018 | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, While process... |
| CVE-2017-14888 | — | — | 0.2% | Dec 7, 2018 | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Userspace can... |
| CVE-2017-18318 | — | — | 1.3% | Nov 28, 2018 | Missing validation check on CRL issuer name in Snapdragon Automobile, Snapdragon Mobile in versions MSM8996AU, SD 410/12... |
| CVE-2017-18317 | — | — | 0.2% | Nov 28, 2018 | Restrictions related to the modem (sim lock, sim kill) can be bypassed by manipulating the system to issue a deactivatio... |
| CVE-2017-18316 | — | — | 0.2% | Nov 28, 2018 | Secure application can access QSEE kernel memory through Ontario kernel driver in Snapdragon Automobile, Snapdragon Mobi... |
| CVE-2017-18315 | — | — | 0.2% | Nov 28, 2018 | Buffer over-read vulnerabilities in an older version of ASN.1 parser in Snapdragon Mobile in versions SD 600. |
| CVE-2017-11078 | — | — | 0.2% | Nov 27, 2018 | In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while process... |
| CVE-2017-17550 | — | — | 0.5% | Nov 10, 2018 | ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd actio... |
| CVE-2017-8931 | — | — | 1.5% | Oct 30, 2018 | Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via u... |
| CVE-2017-18281 | — | — | 0.2% | Oct 29, 2018 | A bool variable in Video function, which gets typecasted to int before being read could result in an out of bound read a... |
| CVE-2017-18311 | — | — | 0.2% | Oct 26, 2018 | XPU Master privilege escalation is possible due to improper access control of unused configuration xPU ports where unuse... |
| CVE-2017-18310 | — | — | 0.2% | Oct 26, 2018 | ClientEnv exposes services 0-32 to HLOS in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MSM8909W... |
| CVE-2017-18309 | — | — | 0.2% | Oct 26, 2018 | A micro-core of QMP transportation may cause a macro-core to read from or write to arbitrary memory in Snapdragon Mobile... |
| CVE-2017-18308 | — | — | 0.3% | Oct 26, 2018 | Modem segments are unlocked after authentication, leaving modem segments open to all in Snapdragon Mobile, Snapdragon We... |
| CVE-2017-18124 | — | — | 0.2% | Oct 26, 2018 | During secure boot, addition is performed on uint8 ptrs which led to overflow issue in Small Cell SoC, Snapdragon Automo... |
| CVE-2017-18349 | — | — | 39.0% | Oct 23, 2018 | parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attac... |
| CVE-2017-18313 | — | — | 0.3% | Oct 23, 2018 | Under certain mode of operations, HLOS may be able get direct or indirect access through DXE channels to tamper with the... |
| CVE-2017-18312 | — | — | 0.2% | Oct 23, 2018 | While accessing SafeSwitch services, third party can manipulate a given device and perform unauthorized operation due to... |
| CVE-2017-18305 | — | — | 0.2% | Oct 23, 2018 | XBL sec mem dump system call allows complete control of EL3 by unlocking all XPUs if enable fuse is not blown in Snapdra... |
| CVE-2017-18304 | — | — | 0.3% | Oct 23, 2018 | Insufficient memory allocation in boot due to incorrect size being passed could result in out of bounds access in Small ... |
| CVE-2017-18303 | — | — | 0.3% | Oct 23, 2018 | While processing the sensors registry configuration file, if inputs are not validated a buffer overflow will occur in Sn... |
| CVE-2017-18300 | — | — | 0.2% | Oct 23, 2018 | Secure display content could be accessed by third party trusted application after creating a fault in other trusted appl... |
| CVE-2017-18299 | — | — | 0.3% | Oct 23, 2018 | Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Sna... |
| CVE-2017-18298 | — | — | 0.3% | Oct 23, 2018 | Lack of Input Validation in SDMX API can lead to NULL pointer access in Snapdragon Automobile, Snapdragon Mobile and Sna... |
| CVE-2017-18297 | — | — | 0.3% | Oct 23, 2018 | Double memory free while closing TEE SE API Session management in Snapdragon Mobile in version SD 425, SD 430, SD 450, S... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now