2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-18292Secure app running in non secure space can restart TZ by calling Widevine app API repeatedly in Snapdragon Automobile, S...
CVE-2017-18283Possible memory corruption when Read Val Blob Req is received with invalid parameters in Snapdragon Mobile in version QC...
CVE-2017-18282Non-secure SW can cause SDCC to generate secure bus accesses, which may expose RPM access in Snapdragon Mobile, Snapdrag...
CVE-2017-18277When dynamic memory allocation fails, currently the process sleeps for one second and continues with infinite loop witho...
CVE-2017-18172In a device, with screen size 1440x2560, the check of contiguous buffer will overflow on certain buffer size resulting i...
CVE-2017-18171Improper input validation for GATT data packet received in Bluetooth Controller function can lead to possible memory cor...
CVE-2017-18170Improper input validation in Bluetooth Controller function can lead to possible memory corruption in Snapdragon Mobile i...
CVE-2017-18348Splunk Enterprise 6.6.x, when configured to run as root but drop privileges to a specific non-root account, allows local...
CVE-2017-17176The hardware security module of Mate 9 and Mate 9 Pro Huawei smart phones with the versions earlier before MHA-AL00BC00B...
CVE-2017-5934Cross-site scripting (XSS) vulnerability in the link dialogue in GUI editor in MoinMoin before 1.9.10 allows remote atta...
CVE-2017-1231MEDIUM4.4IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-...
CVE-2017-5658The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authoriz...
CVE-2017-2751A BIOS password extraction vulnerability has been reported on certain consumer notebooks with firmware F.22 and others. ...
CVE-2017-7908A heap-based buffer overflow exists in the third-party product Gigasoft, v5 and prior, included in GE Communicator 3.15 ...
CVE-2017-1649MEDIUM5.4IBM Rational Quality Manager (RQM) 5.0 through 5.02 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This v...
CVE-2017-15608Inedo ProGet before 5.0 Beta5 has CSRF, allowing an attacker to change advanced settings.
CVE-2017-5639Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-18314In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8...
CVE-2017-18302In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 8...
CVE-2017-18301In Small Cell SoC and Snapdragon (Automobile, Mobile, Wear) in version FSM9055, FSM9955, MDM9607, MDM9640, MDM9650, MSM8...
CVE-2017-18280In Snapdragon (Automobile, Mobile, Wear) in version MDM9607, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, ...
CVE-2017-2877CRITICAL9.8A missing error check exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera running application fi...
CVE-2017-2876HIGH7.5An exploitable buffer overflow vulnerability exists in the Multi-Camera interface used by the Foscam C1 Indoor HD Camera...
CVE-2017-2873HIGH7.2An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Ca...
CVE-2017-2879MEDIUM5.3An exploitable buffer overflow vulnerability exists in the UPnP implementation used by the Foscam C1 Indoor HD Camera ru...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now