9.8
CVE-2017-17833
- EPSS 1.15%
- Veröffentlicht 23.04.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:18:46
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
OpenSLP releases in the 1.0.2 and 1.1.0 code streams have a heap-related memory corruption issue which may manifest itself as a denial-of-service or a remote code-execution vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Debian ≫ Debian Linux Version7.0
Canonical ≫ Ubuntu Linux Version14.04 SwEditionlts
Canonical ≫ Ubuntu Linux Version16.04 SwEditionlts
Redhat ≫ Enterprise Linux Desktop Version6.0
Redhat ≫ Enterprise Linux Desktop Version7.0
Redhat ≫ Enterprise Linux Server Version6.0
Redhat ≫ Enterprise Linux Server Version7.0
Redhat ≫ Enterprise Linux Server Aus Version7.6
Redhat ≫ Enterprise Linux Server Eus Version7.5
Redhat ≫ Enterprise Linux Server Eus Version7.6
Redhat ≫ Enterprise Linux Server Tus Version7.6
Redhat ≫ Enterprise Linux Workstation Version6.0
Redhat ≫ Enterprise Linux Workstation Version7.0
Lenovo ≫ Thinkserver Rd350g Firmware Version-
Lenovo ≫ Thinkserver Rd350x Firmware Version-
Lenovo ≫ Thinkserver Rd450x Firmware Version-
Lenovo ≫ Thinksystem Hr630x Firmware Version-
Lenovo ≫ Thinksystem Hr650x Firmware Version-
Lenovo ≫ Thinksystem Sr630 Firmware Version-
Lenovo ≫ Flex System Fc3171 8gb San Switch Firmware Version < 9.1.13.02.00
Lenovo ≫ Storage N3310 Firmware Version < 4.53.351
Lenovo ≫ Storage N4610 Firmware Version < 4.53.351
Lenovo ≫ Bm Nextscale Fan Power Controller Version < 24p-2.15
Lenovo ≫ Fan Power Controller Version < 30r-1.13
Lenovo ≫ Xclarity Administrator Version < 1.4.0
Lenovo ≫ Thinkserver Rd340 Firmware Version < 50.00
Lenovo ≫ Thinkserver Rd350 Firmware Version < 4.53.351
Lenovo ≫ Thinkserver Rd440 Firmware Version <= 50.00
Lenovo ≫ Thinkserver Rd450 Firmware Version < 4.53.351
Lenovo ≫ Thinkserver Rd550 Firmware Version < 4.53.351
Lenovo ≫ Thinkserver Rd540 Firmware Version < 50.00
Lenovo ≫ Thinkserver Rd640 Firmware Version < 50.00
Lenovo ≫ Thinkserver Rd650 Firmware Version < 4.53.351
Lenovo ≫ Thinkserver Rq750 Firmware Version < 1.40
Lenovo ≫ Thinkserver Rs160 Firmware Version < 2.32
Lenovo ≫ Thinkserver Sd350 Firmware Version-
Lenovo ≫ Thinkserver Td340 Firmware Version < 46.00
Lenovo ≫ Thinkserver Td350 Firmware Version < 4.53.351
Lenovo ≫ Thinkserver Ts460 Firmware Version < 2.32
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.15% | 0.778 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.