2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2017-18296Access control on applications is not applied while accessing SafeSwitch services can lead to improper access in Snapdra...
CVE-2017-18295Possible buffer overflow if input is not null terminated in DSP Service module in Snapdragon Automobile, Snapdragon Mobi...
CVE-2017-18294While reading file class type from ELF header, a buffer overread may happen if the ELF file size is less than the size o...
CVE-2017-18293When a particular GPIO is protected by blocking access to the corresponding GPIO resource registers, the protection can ...
CVE-2017-18292Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, S...
CVE-2017-18283Possible memory corruption when Read Val Blob Req is received with invalid parameters in Snapdragon Mobile in version QC...
CVE-2017-18282Non-secure SW can cause SDCC to generate secure bus accesses, which may expose RPM access in Snapdragon Mobile, Snapdrag...
CVE-2017-18277When dynamic memory allocation fails, currently the process sleeps for one second and continues with infinite loop witho...
CVE-2017-18172In a device, with screen size 1440x2560, the check of contiguous buffer will overflow on certain buffer size resulting i...
CVE-2017-18171Improper input validation for GATT data packet received in Bluetooth Controller function can lead to possible memory cor...
CVE-2017-18170Improper input validation in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile i...
CVE-2017-18348Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local...
CVE-2017-17176The hardware security module of Mate 9 and Mate 9 Pro Huawei smart phones with the versions earlier before MHA-AL00BC00B...
CVE-2017-5934Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote atta...
CVE-2017-5658The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authoriz...
CVE-2017-2751A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. ...
CVE-2017-7908A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 ...
CVE-2017-15608Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
CVE-2017-5639Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-18314In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8...
CVE-2017-18302In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 8...
CVE-2017-18301In Small Cell SoC and Snapdragon (Automobile, Mobile, Wear) in version FSM9055, FSM9955, MDM9607, MDM9640, MDM9650, MSM8...
CVE-2017-18280In Snapdragon (Automobile, Mobile, Wear) in version MDM9607, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, ...
CVE-2017-6913Cross-site scripting (XSS) vulnerability in the Open-Xchange webmail before 7.6.3-rev28 allows remote attackers to injec...
CVE-2017-15844In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, while proces...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now