← Vulnerability feed

Vulnerability record · CVE-2017-17482 · published 7 February 2018

CVE-2017-17482: Hp openvms memory buffer overflow vulnerability

Hp · Openvms

An issue was discovered in OpenVMS through V8.4-2L2 on Alpha and through V8.4-2L1 on IA64, and VAX/VMS 4.0 and later. A malformed DCL command table may result in a buffer overflow allowing a local privilege escalation when a non-privileged account enters a crafted command line. This bug is exploitable on VAX and Alpha and may cause a process crash on IA64. Software was affected regardless of whether it was directly shipped by VMS Software, Inc. (VSI), HPE, HP, Compaq, or Digital Equipment Corporation.

7.8 CVSS 3.0 High EPSS 0.64% · top 51.7% CWE-119 · Memory buffer overflow
7.8CVSS 3.0 base score, v2 4.6
0.64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in OpenVMS through V8.4-2L2 on Alpha and through V8.4-2L1 on IA64, and VAX/VMS 4.0 and later. A malformed DCL command table may result in a buffer overflow allowing a local privilege escalation when a non-privileged account enters a crafted command line. This bug is exploitable on VAX and Alpha and may cause a process crash on IA64. Software was affected regardless of whether it was directly shipped by VMS Software, Inc. (VSI), HPE, HP, Compaq, or Digital Equipment Corporation.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-17482 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-5120Hp openvms memory buffer overflow vulnerabilityStack-based buffer overflow in the Process Software MultiNet finger service (aka FINGERD) for HP OpenVMS 8.3 allows remote attackers to execute arbit…EPSS 9.9%7.5CVE-2007-0139Hp openvms vulnerabilityUnspecified vulnerability in the DECnet-Plus 7.3-2 feature in DECnet/OSI 7.3-2 for OpenVMS ALPHA, and the DECnet-Plus 7.3 feature in DECnet/OSI 7.3 f…EPSS 2.2%7.2CVE-2008-4052Hp openvms memory buffer overflow vulnerabilityStack-based buffer overflow in SMGSHR.EXE in OpenVMS for Integrity Servers 8.2-1, 8.3, and 8.3-1H1 and OpenVMS ALPHA 7.3-2, 8.2, and 8.3 allows local…EPSS 0.48%7.2CVE-2008-3947Hp openvms improper input validation vulnerabilityDCL (aka the CLI) in OpenVMS Alpha 8.3 allows local users to gain privileges via a long command line.EPSS 0.44%6.9CVE-2012-2010Hp openvms permissions and access controls vulnerabilityThe ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM sys…EPSS 0.39%6.8CVE-2010-1973Hp openvms vulnerabilityUnspecified vulnerability in the Auditing subsystem in HP OpenVMS 8.3, 8.2, 7.3-2, and earlier on the ALPHA platform, and 8.3-1H1, 8.3, 8.2-1, and ea…EPSS 0.28%5.7CVE-2010-4110Hp openvms vulnerabilityUnspecified vulnerability in HP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform on Integrity servers allows local users to gain privileges or c…EPSS 0.28%5.0CVE-2012-3277Hp openvms vulnerabilityHP OpenVMS 8.3, 8.3-1H1, and 8.4 on the Itanium platform and 7.3-2, 8.2, 8.3, and 8.4 on the Alpha platform does not properly implement the LOGIN and…EPSS 2.4%

Source: NIST National Vulnerability Database (record CVE-2017-17482), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.