2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5376 | — | — | 3.2% | Jun 11, 2018 | Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45... |
| CVE-2017-5375 | — | — | 33.4% | Jun 11, 2018 | JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T... |
| CVE-2017-5374 | — | — | 1.8% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume... |
| CVE-2017-5373 | — | — | 3.3% | Jun 11, 2018 | Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corr... |
| CVE-2017-3208 | — | — | 4.0% | Jun 11, 2018 | The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows extern... |
| CVE-2017-3207 | — | — | 8.2% | Jun 11, 2018 | The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class inst... |
| CVE-2017-3206 | — | — | 3.7% | Jun 11, 2018 | The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external ... |
| CVE-2017-3203 | — | — | 6.3% | Jun 11, 2018 | The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externa... |
| CVE-2017-3202 | — | — | 8.2% | Jun 11, 2018 | The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instan... |
| CVE-2017-3201 | — | — | 5.4% | Jun 11, 2018 | The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0 derives class ins... |
| CVE-2017-3200 | HIGH | 8.1 | 6.1% | Jun 11, 2018 | The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary c... |
| CVE-2017-3199 | HIGH | 8.1 | 6.1% | Jun 11, 2018 | The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.External... |
| CVE-2017-1405 | MEDIUM | 4.4 | 0.5% | Jun 8, 2018 | IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other updates without sufficien... |
| CVE-2017-12078 | HIGH | 7.2 | 2.4% | Jun 8, 2018 | Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenti... |
| CVE-2017-12075 | HIGH | 7.2 | 1.9% | Jun 8, 2018 | Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote auth... |
| CVE-2017-6294 | — | — | 0.2% | Jun 7, 2018 | In Android before the 2018-06-05 security patch level, NVIDIA Tegra X1 TZ contains a possible out of bounds write due to... |
| CVE-2017-6292 | — | — | 0.2% | Jun 7, 2018 | In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due ... |
| CVE-2017-6290 | — | — | 0.2% | Jun 7, 2018 | In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due ... |
| CVE-2017-6779 | — | — | 2.0% | Jun 7, 2018 | Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco c... |
| CVE-2017-16226 | — | — | 3.6% | Jun 7, 2018 | The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user i... |
| CVE-2017-16225 | — | — | 1.2% | Jun 7, 2018 | aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled an... |
| CVE-2017-16224 | — | — | 0.9% | Jun 7, 2018 | st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) t... |
| CVE-2017-16223 | — | — | 2.0% | Jun 7, 2018 | nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to ... |
| CVE-2017-16222 | — | — | 1.7% | Jun 7, 2018 | elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the f... |
| CVE-2017-16221 | — | — | 2.0% | Jun 7, 2018 | yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesyst... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now