2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1418 | MEDIUM | 4 | 0.3% | Nov 26, 2018 | IBM Integration Bus 9.0.0.0, 9.0.0.11, 10.0.0.0, and 10.0.0.14 (including IBM WebSphere Message Broker 8.0.0.0 and 8.0.0... |
| CVE-2017-17550 | — | — | 0.5% | Nov 10, 2018 | ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd actio... |
| CVE-2017-1119 | MEDIUM | 4.3 | 1.3% | Nov 9, 2018 | IBM Marketing Operations 9.1.0, 9.1.2, and 10.1 could allow a remote attacker to obtain sensitive information. An attack... |
| CVE-2017-1609 | MEDIUM | 5.4 | 1.0% | Nov 2, 2018 | IBM Quality Manager (RQM) 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerabi... |
| CVE-2017-8931 | — | — | 1.5% | Oct 30, 2018 | Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via u... |
| CVE-2017-18281 | — | — | 0.2% | Oct 29, 2018 | A bool variable in Video function, which gets typecasted to int before being read could result in an out of bound read a... |
| CVE-2017-18311 | — | — | 0.2% | Oct 26, 2018 | XPU Master privilege escalation is possible due to improper access control of unused configuration xPU ports where unuse... |
| CVE-2017-18310 | — | — | 0.2% | Oct 26, 2018 | ClientEnv exposes services 0-32 to HLOS in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MSM8909W... |
| CVE-2017-18309 | — | — | 0.2% | Oct 26, 2018 | A micro-core of QMP transportation may cause a macro-core to read from or write to arbitrary memory in Snapdragon Mobile... |
| CVE-2017-18308 | — | — | 0.3% | Oct 26, 2018 | Modem segments are unlocked after authentication, leaving modem segments open to all in Snapdragon Mobile, Snapdragon We... |
| CVE-2017-18124 | — | — | 0.2% | Oct 26, 2018 | During secure boot, addition is performed on uint8 ptrs which led to overflow issue in Small Cell SoC, Snapdragon Automo... |
| CVE-2017-18349 | — | — | 39.0% | Oct 23, 2018 | parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attac... |
| CVE-2017-18313 | — | — | 0.3% | Oct 23, 2018 | Under certain mode of operations, HLOS may be able get direct or indirect access through DXE channels to tamper with the... |
| CVE-2017-18312 | — | — | 0.2% | Oct 23, 2018 | While accessing SafeSwitch services, third party can manipulate a given device and perform unauthorized operation due to... |
| CVE-2017-18305 | — | — | 0.2% | Oct 23, 2018 | XBL sec mem dump system call allows complete control of EL3 by unlocking all XPUs if enable fuse is not blown in Snapdra... |
| CVE-2017-18304 | — | — | 0.3% | Oct 23, 2018 | Insufficient memory allocation in boot due to incorrect size being passed could result in out of bounds access in Small ... |
| CVE-2017-18303 | — | — | 0.3% | Oct 23, 2018 | While processing the sensors registry configuration file, if inputs are not validated a buffer overflow will occur in Sn... |
| CVE-2017-18300 | — | — | 0.2% | Oct 23, 2018 | Secure display content could be accessed by third party trusted application after creating a fault in other trusted appl... |
| CVE-2017-18299 | — | — | 0.3% | Oct 23, 2018 | Improper translation table consolidation logic leads to resource exhaustion and QSEE error in Snapdragon Automobile, Sna... |
| CVE-2017-18298 | — | — | 0.3% | Oct 23, 2018 | Lack of Input Validation in SDMX API can lead to NULL pointer access in Snapdragon Automobile, Snapdragon Mobile and Sna... |
| CVE-2017-18297 | — | — | 0.3% | Oct 23, 2018 | Double memory free while closing TEE SE API Session management in Snapdragon Mobile in version SD 425, SD 430, SD 450, S... |
| CVE-2017-18296 | — | — | 0.3% | Oct 23, 2018 | Access control on applications is not applied while accessing SafeSwitch services can lead to improper access in Snapdra... |
| CVE-2017-18295 | — | — | 0.3% | Oct 23, 2018 | Possible buffer overflow if input is not null terminated in DSP Service module in Snapdragon Automobile, Snapdragon Mobi... |
| CVE-2017-18294 | — | — | 0.3% | Oct 23, 2018 | While reading file class type from ELF header, a buffer overread may happen if the ELF file size is less than the size o... |
| CVE-2017-18293 | — | — | 0.3% | Oct 23, 2018 | When a particular GPIO is protected by blocking access to the corresponding GPIO resource registers, the protection can ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now