2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8407 | HIGH | 8.8 | 1.2% | Jul 2, 2019 | An issue was discovered on D-Link DCS-1130 devices. The device provides a user with the capability of changing the admin... |
| CVE-2017-18378 | HIGH | 8.4 | 8.2% | Jun 11, 2019 | In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is pa... |
| CVE-2017-6261 | HIGH | 8.2 | 0.4% | Jun 5, 2019 | NVIDIA Vibrante Linux version 1.1, 2.0, and 2.2 contains a vulnerability in the user space driver in which protection me... |
| CVE-2017-14853 | HIGH | 8.6 | 3.8% | Jun 3, 2019 | The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search... |
| CVE-2017-14852 | HIGH | 8.6 | 1.0% | Jun 3, 2019 | An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due... |
| CVE-2017-18279 | HIGH | 7.8 | 0.2% | May 6, 2019 | Lack of check of buffer length before copying can lead to buffer overflow in camera module in Small Cell SoC, Snapdragon... |
| CVE-2017-11430 | HIGH | 7.7 | 2.3% | Apr 17, 2019 | OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization ... |
| CVE-2017-11429 | HIGH | 7.7 | 2.4% | Apr 17, 2019 | Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in su... |
| CVE-2017-11428 | HIGH | 7.7 | 2.5% | Apr 17, 2019 | OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs ... |
| CVE-2017-11427 | HIGH | 7.7 | 4.4% | Apr 17, 2019 | OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs... |
| CVE-2017-3139 | HIGH | 7.5 | 1.6% | Apr 9, 2019 | A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to m... |
| CVE-2017-17544 | HIGH | 7.2 | 1.7% | Apr 9, 2019 | A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin use... |
| CVE-2017-16775 | HIGH | 7.1 | 1.1% | Apr 1, 2019 | Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0... |
| CVE-2017-7655 | HIGH | 7.5 | 1.9% | Mar 27, 2019 | In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library whi... |
| CVE-2017-18364 | HIGH | 7.4 | 1.4% | Mar 27, 2019 | phpFK lite has XSS via the faq.php, members.php, or search.php query string or the user.php user parameter. |
| CVE-2017-7510 | HIGH | 8.8 | 1.0% | Mar 25, 2019 | In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST int... |
| CVE-2017-16255 | HIGH | 8.1 | 1.2% | Mar 21, 2019 | An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware versio... |
| CVE-2017-16254 | HIGH | 8.1 | 1.2% | Mar 21, 2019 | An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware versio... |
| CVE-2017-16253 | HIGH | 8.1 | 1.1% | Mar 21, 2019 | An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware versio... |
| CVE-2017-0938 | HIGH | 7.5 | 21.0% | Feb 12, 2019 | Denial of Service attack in airMAX < 8.3.2 , airMAX < 6.0.7 and EdgeMAX < 1.9.7 allow attackers to use the Discovery Pro... |
| CVE-2017-18359 | HIGH | 7.5 | 3.0% | Jan 25, 2019 | PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_A... |
| CVE-2017-3145 | HIGH | 7.5 | 27.9% | Jan 16, 2019 | BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-a... |
| CVE-2017-3144 | HIGH | 7.5 | 72.7% | Jan 16, 2019 | A vulnerability stemming from failure to properly clean up closed OMAPI connections can lead to exhaustion of the pool o... |
| CVE-2017-3143 | HIGH | 7.5 | 18.2% | Jan 16, 2019 | An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSI... |
| CVE-2017-3141 | HIGH | 7.2 | 1.4% | Jan 16, 2019 | The BIND installer on Windows uses an unquoted service path which can enable a local user to achieve privilege escalatio... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now