Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Loading...
Loading...
Score elevated to 9.0 because EPSS predicts 94% probability of exploitation within the next 30 days (top 0.1% of all CVEs). NVD baseline CVSS 5.6 retained for reference. Confidence: see factors.
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
January 4, 2018
May 28, 2026
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Every vendor that published an advisory referencing this CVE — pulled from our cve_vendor_advisories aggregation. Click any row for the vendor's original advisory page.
RHSA-2018:0010 — Important
RHSA-2018:0016 — Important
RHSA-2018:0017 — Important
RHSA-2018:0018 — Important
RHSA-2018:0020 — Important
RHSA-2018:0021 — Important
RHSA-2018:0022 — Important
RHSA-2018:0151 — Important
RHSA-2018:0182 — Important
RHSA-2018:0292 — Important
RHSA-2018:0464 — Important
RHSA-2018:0496 — Important
RHSA-2018:0512 — Important
RHSA-2018:0654 — Important
Firefox vulnerabilities
NVIDIA graphics drivers vulnerability
WebKitGTK+ vulnerabilities
Linux kernel vulnerabilities
Linux kernel (Xenial HWE) vulnerabilities
Linux kernel vulnerabilities
Linux kernel (HWE) vulnerabilities
Linux kernel vulnerabilities
Linux kernel (Trusty HWE) vulnerabilities
Linux kernel (KVM) vulnerabilities
Linux kernel vulnerabilities
Every time one of our enrichment pipelines (NVD, MITRE cvelistV5, EPSS, CISA KEV, GHSA, OSV, vendor advisories) ran against this CVE. Most recent first.
Working exploit code is in the public domain (4 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
The demo of the speculative execution attack Spectre (CVE-2017-5753, CVE-2017-5715).
Open source ↗2018年1月2日 (CVE-2017-5753 和 CVE-2017-5715) "幽灵" Spectre 漏洞利用
Open source ↗Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)
Open source ↗Spectre (CVE-2017-5753) (CVE-2017-5715). Not By Me. Collected from Book.
Open source ↗Multiple CPUs - 'Spectre' Information Disclosure
Open source ↗This CVE was central to one or more publicly-documented breaches. Each card links to authoritative reporting at the time of the incident.
Speculative-execution side-channel attacks against virtually every modern CPU (Intel, AMD, ARM). Required hardware-firmware updates and OS kernel changes across the industry.
Source: ZDNetSee which npm, PyPI, Go, and Maven packages are affected by CVE-2017-5753
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.