2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-17172Huawei smart phones LYO-L21 with software LYO-L21C479B107, LYO-L21C479B107 have a privilege escalation vulnerability. An...
CVE-2017-3936MEDIUM6.2OS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5....
CVE-2017-3907MEDIUM5.4Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Se...
CVE-2017-3968HIGH7.5Session fixation vulnerability in the web interface in McAfee Network Security Manager (NSM) before 8.2.7.42.2 and McAfe...
CVE-2017-17443OPC Foundation Local Discovery Server (LDS) 1.03.370 required a security update to resolve multiple vulnerabilities that...
CVE-2017-11672The OPC Foundation Local Discovery Server (LDS) before 1.03.367 is installed as a Windows Service without adding double ...
CVE-2017-15695When an Apache Geode server versions 1.0.0 to 1.4.0 is configured with a security manager, a user with DATA:WRITE privil...
CVE-2017-16652An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.1...
CVE-2017-18070In wma_ndp_end_response_event_handler(), the variable len_end_rsp is a uint32 which can be overflowed if the value of va...
CVE-2017-15857In the camera driver, an out-of-bounds access can occur due to an error in copying region params from user space in all ...
CVE-2017-15854The value of fix_param->num_chans is received from firmware and if it is too large, an integer overflow can occur in wma...
CVE-2017-15843Due to a race condition in a bus driver, a double free in msm_bus_floor_vote_context() can potentially occur in all Andr...
CVE-2017-15842Buffer might get used after it gets freed due to unlocking the mutex before freeing the buffer in all Android releases f...
CVE-2017-18291An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET user parameter.
CVE-2017-18290An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET sort_direction parame...
CVE-2017-18289An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter.
CVE-2017-18288An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET game parameter.
CVE-2017-18287An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search paramete...
CVE-2017-3962MEDIUM5.6Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Sec...
CVE-2017-3960MEDIUM5.9Exploitation of Authorization vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2....
CVE-2017-7848RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects...
CVE-2017-7847Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affec...
CVE-2017-7846It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed...
CVE-2017-7845A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used fo...
CVE-2017-7844A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image ca...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now