2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1418MEDIUM4IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0...
CVE-2017-17550ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd actio...
CVE-2017-1119MEDIUM4.3IBM Marketing Operations 9.1.0, 9.1.2, and 10.1 could allow a remote attacker to obtain sensitive information. An attack...
CVE-2017-1609MEDIUM5.4IBM Quality Manager (RQM) 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerabi...
CVE-2017-8931Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via u...
CVE-2017-18281A bool variable in Video function, which gets typecasted to int before being read could result in an out of bound read a...
CVE-2017-18311XPU Master privilege escalation is possible due to improper access control of unused configuration xPU ports where unuse...
CVE-2017-18310ClientEnv exposes services 0-32 to HLOS in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MSM8909W...
CVE-2017-18309A micro-core of QMP transportation may cause a macro-core to read from or write to arbitrary memory in Snapdragon Mobile...
CVE-2017-18308Modem segments are unlocked after authentication, leaving modem segments open to all in Snapdragon Mobile, Snapdragon We...
CVE-2017-18124During secure boot, addition is performed on uint8 ptrs which led to overflow issue in Small Cell SoC, Snapdragon Automo...
CVE-2017-18349parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attac...
CVE-2017-18313Under certain mode of operations, HLOS may be able get direct or indirect access through DXE channels to tamper with the...
CVE-2017-18312While accessing SafeSwitch services, third party can manipulate a given device and perform unauthorized operation due to...
CVE-2017-18305XBL sec mem dump system call allows complete control of EL3 by unlocking all XPUs if enable fuse is not blown in Snapdra...
CVE-2017-18304Insufficient memory allocation in boot due to incorrect size being passed could result in out of bounds access in Small ...
CVE-2017-18303While processing the sensors registry configuration file, if inputs are not validated a buffer overflow will occur in Sn...
CVE-2017-18300Secure display content could be accessed by third party trusted application after creating a fault in other trusted appl...
CVE-2017-18299Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Sna...
CVE-2017-18298Lack of Input Validation in SDMX API can lead to NULL pointer access in Snapdragon Automobile, Snapdragon Mobile and Sna...
CVE-2017-18297Double memory free while closing TEE SE API Session management in Snapdragon Mobile in version SD 425, SD 430, SD 450, S...
CVE-2017-18296Access control on applications is not applied while accessing SafeSwitch services can lead to improper access in Snapdra...
CVE-2017-18295Possible buffer overflow if input is not null terminated in DSP Service module in Snapdragon Automobile, Snapdragon Mobi...
CVE-2017-18294While reading file class type from ELF header, a buffer overread may happen if the ELF file size is less than the size o...
CVE-2017-18293When a particular GPIO is protected by blocking access to the corresponding GPIO resource registers, the protection can ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now