← Vulnerability feed

Vulnerability record · CVE-2017-3242 · published 27 January 2017

CVE-2017-3242: Oracle vm server improper input validation vulnerability

Oracle · Vm Server

Vulnerability in the Oracle VM Server for Sparc component of Oracle Sun Systems Products Suite (subcomponent: LDOM Manager). Supported versions that are affected are 3.2 and 3.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM Server for Sparc executes to compromise Oracle VM Server for Sparc. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM Server for Sparc, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM Server for Sparc. CVSS v3.0 Base Score 5.9 (Availability impacts).

5.9 CVSS 3.0 Medium EPSS 0.35% · top 73.8% CWE-20 · Improper input validation
5.9CVSS 3.0 base score, v2 1.9
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Vulnerability in the Oracle VM Server for Sparc component of Oracle Sun Systems Products Suite (subcomponent: LDOM Manager). Supported versions that are affected are 3.2 and 3.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM Server for Sparc executes to compromise Oracle VM Server for Sparc. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM Server for Sparc, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM Server for Sparc. CVSS v3.0 Base Score 5.9 (Availability impacts).

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-3242 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4448Hp icewall federation agent vulnerabilityFormat string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.EPSS 7.0%9.8CVE-2015-8668Libtiff out-of-bounds write vulnerabilityHeap-based buffer overflow in the PackBitsPreEncode function in tif_packbits.c in bmp2tiff in libtiff 4.0.6 and earlier allows remote attackers to ex…EPSS 14%9.3CVE-2014-1490Mozilla firefox race condition vulnerabilityRace condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24…EPSS 3.9%8.8CVE-2016-3710Debian linux memory buffer overflow vulnerabilityThe VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute ar…EPSS 0.92%8.8CVE-2016-3960Xen permissions and access controls vulnerabilityInteger overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privi…EPSS 0.46%8.8CVE-2016-1950Mozilla network security services memory buffer overflow vulnerabilityHeap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox…EPSS 4.2%8.4CVE-2016-4480Oracle vm server permissions and access controls vulnerabilityThe guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit …EPSS 0.54%7.8CVE-2016-3991Oracle vm server memory buffer overflow vulnerabilityHeap-based buffer overflow in the loadImage function in the tiffcrop tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of s…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2017-3242), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.