2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-5376Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45...
CVE-2017-5375JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T...
CVE-2017-5374Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume...
CVE-2017-5373Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corr...
CVE-2017-3208The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows extern...
CVE-2017-3207The Java implementations of AMF3 deserializers in WebORB for Java by Midnight Coders, version 5.1.1.0, derive class inst...
CVE-2017-3206The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external ...
CVE-2017-3203The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externa...
CVE-2017-3202The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0, may allow instan...
CVE-2017-3201The Java implementation of AMF3 deserializers used in Flamingo amf-serializer by Exadel, version 2.2.0 derives class ins...
CVE-2017-3200HIGH8.1The Java implementation of AMF3 deserializers used in GraniteDS, version 3.1.1.G, may allow instantiation of arbitrary c...
CVE-2017-3199HIGH8.1The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.External...
CVE-2017-1405MEDIUM4.4IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other updates without sufficien...
CVE-2017-12078HIGH7.2Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenti...
CVE-2017-12075HIGH7.2Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote auth...
CVE-2017-6294In Android before the 2018-06-05 security patch level, NVIDIA Tegra X1 TZ contains a possible out of bounds write due to...
CVE-2017-6292In Android before the 2018-06-05 security patch level, NVIDIA TLZ TrustZone contains a possible out of bounds write due ...
CVE-2017-6290In Android before the 2018-06-05 security patch level, NVIDIA TLK TrustZone contains a possible out of bounds write due ...
CVE-2017-6779Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco c...
CVE-2017-16226The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user i...
CVE-2017-16225aegir is a module to help automate JavaScript project management. Version 12.0.0 through and including 12.0.7 bundled an...
CVE-2017-16224st is a module for serving static files. An attacker is able to craft a request that results in an HTTP 301 (redirect) t...
CVE-2017-16223nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to ...
CVE-2017-16222elding is a simple web server. elding is vulnerable to a directory traversal issue, allowing an attacker to access the f...
CVE-2017-16221yzt is a simple file server. yzt is vulnerable to a directory traversal issue, giving an attacker access to the filesyst...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now