2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2017-20240MEDIUM5.9Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq...
CVE-2017-20239MEDIUM6.1MDwiki contains a cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript by inj...
CVE-2017-20233MEDIUM5.4Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correc...
CVE-2017-20219MEDIUM6.1Serviio PRO 1.8 DLNA Media Streaming Server contains a DOM-based cross-site scripting vulnerability that allows attacker...
CVE-2017-20209MEDIUM6.1Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insu...
CVE-2017-20199MEDIUM6.5A vulnerability was found in Buttercup buttercup-browser-extension up to 0.14.2. Affected by this vulnerability is an un...
CVE-2017-13318MEDIUM5.7In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. Thi...
CVE-2017-13317MEDIUM5.7In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input val...
CVE-2017-20196MEDIUM6.3A vulnerability was found in Itechscripts School Management Software 2.75. It has been classified as critical. This affe...
CVE-2017-13322MEDIUM5.5In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services d...
CVE-2017-13308MEDIUM6.7In tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to i...
CVE-2017-13321MEDIUM5.5In SensorService::isDataInjectionEnabled of frameworks/native/services/sensorservice/SensorService.cpp, there is a possi...
CVE-2017-13320MEDIUM6.5In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead...
CVE-2017-18307MEDIUM5.5Information disclosure possible while audio playback.
CVE-2017-18306MEDIUM5.5Information disclosure due to uninitialized variable.
CVE-2017-13313MEDIUM6.5In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resou...
CVE-2017-13311MEDIUM6.7In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions...
CVE-2017-13309MEDIUM5.5In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This cou...
CVE-2017-13227MEDIUM5.5In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could le...
CVE-2017-20195MEDIUM5.5A vulnerability was found in LUNAD3v AreaLoad up to 1a1103182ed63a06dde63d1712f3262eda19c3ec. It has been rated as criti...
CVE-2017-20194MEDIUM5.3The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and includi...
CVE-2017-20193MEDIUM6.1The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions u...
CVE-2017-20192MEDIUM6.1The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters su...
CVE-2017-3772MEDIUM5.5A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a ...
CVE-2017-20188MEDIUM4.7A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerabili...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now