14,642 vulnerabilities published in 2017
pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the p
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
A vulnerability in the ConfD server component of Cisco Elastic Services Controllers could allow an authenticated, local
A vulnerability in the Virtual Network Function Manager's (VNFM) logging function of Cisco Ultra Services Platform could
A vulnerability in the ConfD server in Cisco Ultra Services Platform could allow an authenticated, local attacker to vie
A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwg
In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.
In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.
In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwr
In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.
In all Android releases from CAF using the Linux kernel, some regions of memory were not protected during boot.
In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.
In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters.
In all Android releases from CAF using the Linux kernel, a memory structure in a camera driver is not properly protected
In all Android releases from CAF using the Linux kernel, userspace-controlled parameters for flash initialization are no
An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to caus
A remote denial of service vulnerability in libvpx in Mediaserver could enable an attacker to use a specially crafted fi
A remote denial of service vulnerability in libhevc in Mediaserver could enable an attacker to use a specially crafted f
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to caus
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to caus
An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to access data outside o
An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data
An information disclosure vulnerability in libziparchive could enable a local malicious application to access data outsi
In Wireshark 2.2.7, overly deep mp4 chunks may cause stack exhaustion (uncontrolled recursion) in the dissect_mp4_box fu
In Wireshark 2.2.7, deeply nested DAAP data may cause stack exhaustion (uncontrolled recursion) in the dissect_daap_one_
Microsoft Windows 10 1607 and 1703, and Windows Server 2016 allow an authenticated attacker to modify the C:\Users\DEFAU
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Ser
A security feature bypass vulnerability exists in Microsoft Office software when it improperly handles the parsing of fi
Microsoft Windows 10 1511, 1607, and 1703, and Windows Server 2016 allow an unauthenticated attacker to send a specially
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged u
Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged u
QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users
QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest O
sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resu
The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-bas
The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use
The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to c
The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to caus
GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an
JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) v
IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user
IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper acc
IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could
Scan for 2017 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started