2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-18285The Gentoo app-backup/burp package before 2.1.32 has incorrect group ownership of the /etc/burp directory, which might a...
CVE-2017-18284The Gentoo app-backup/burp package before 2.1.32 sets the ownership of the PID file directory to the burp account, which...
CVE-2017-2860HIGH7.5An exploitable denial-of-service vulnerability exists in the lookup entry functionality of KeyTrees in Natus Xltek Neuro...
CVE-2017-2858HIGH7.5An exploitable denial-of-service vulnerability exists in the traversal of lists functionality of Natus Xltek NeuroWorks ...
CVE-2017-2852HIGH7.5An exploitable denial-of-service vulnerability exists in the unserialization of lists functionality of Natus Xltek Neuro...
CVE-2017-6153Features in F5 BIG-IP 13.0.0-13.1.0.3, 12.1.0-12.1.3.1, 11.6.1-11.6.3.1, 11.5.1-11.5.5, or 11.2.1 system that utilizes i...
CVE-2017-17171Some Huawei smart phones have the denial of service (DoS) vulnerability due to the improper processing of malicious para...
CVE-2017-16153gaoxuyan is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in t...
CVE-2017-16062HIGH7.5node-tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished b...
CVE-2017-16061tkinter was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm...
CVE-2017-16047mysqljs was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm...
CVE-2017-16010i18next is a language translation framework. When using the .init method, passing interpolation options without passing ...
CVE-2017-16003windows-build-tools is a module for installing C++ Build Tools for Windows using npm. windows-build-tools versions below...
CVE-2017-1768MEDIUM4.3IBM Security Guardium Big Data Intelligence (SonarG) 3.1 generates an error message that includes sensitive information ...
CVE-2017-14185An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows S...
CVE-2017-9641PI Coresight 2016 R2 contains a cross-site request forgery vulnerability that may allow access to the PI system. OSIsoft...
CVE-2017-1752IBM UrbanCode Deploy 6.1 and 6.2 could allow an authenticated privileged user to obtain highly sensitive information. IB...
CVE-2017-3961LOW3.5Cross-Site Scripting (XSS) vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.4...
CVE-2017-9664In ABB SREA-01 revisions A, B, C: application versions up to 3.31.5, and SREA-50 revision A: application versions up to ...
CVE-2017-14187A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, ...
CVE-2017-17315Huawei DP300 V500R002C00; RP200 V600R006C00; TE30 V100R001C10; V500R002C00; V600R006C00; TE40 V500R002C00; V600R006C00; ...
CVE-2017-17158Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the ver...
CVE-2017-9421Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain ...
CVE-2017-9317Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can g...
CVE-2017-2598MEDIUM4.3Jenkins before versions 2.44, 2.32.2 uses AES ECB block cipher mode without IV for encrypting secrets which makes Jenkin...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now