2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7632 | — | — | 0.8% | Mar 27, 2018 | Cross-site scripting (XSS) vulnerability in File Station of QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and ... |
| CVE-2017-7631 | — | — | 0.8% | Mar 27, 2018 | Cross-site scripting (XSS) vulnerability in the share link function of File Station of QNAP 4.2.6 build 20171026, QTS 4.... |
| CVE-2017-7630 | — | — | 1.1% | Mar 27, 2018 | QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensit... |
| CVE-2017-12319 | MEDIUM | 5.9 | 5.4% | Mar 27, 2018 | A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE So... |
| CVE-2017-12310 | — | — | 0.9% | Mar 27, 2018 | A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remot... |
| CVE-2017-18254 | — | — | 1.8% | Mar 27, 2018 | An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function WriteGIFImage in cod... |
| CVE-2017-18253 | — | — | 1.1% | Mar 27, 2018 | An issue was discovered in ImageMagick 7.0.7. A NULL pointer dereference vulnerability was found in the function LoadOpe... |
| CVE-2017-18252 | — | — | 2.0% | Mar 27, 2018 | An issue was discovered in ImageMagick 7.0.7. The MogrifyImageList function in MagickWand/mogrify.c allows attackers to ... |
| CVE-2017-18251 | — | — | 1.8% | Mar 27, 2018 | An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function ReadPCDImage in code... |
| CVE-2017-18250 | — | — | 1.4% | Mar 27, 2018 | An issue was discovered in ImageMagick 7.0.7. A NULL pointer dereference vulnerability was found in the function LogOpen... |
| CVE-2017-12815 | — | — | 2.0% | Mar 26, 2018 | Analysis of the Bomgar Remote Support Portal JavaStart.jar Applet 52790 and earlier revealed that it is vulnerable to a ... |
| CVE-2017-12410 | — | — | 0.3% | Mar 26, 2018 | It is possible to exploit a Time of Check & Time of Use (TOCTOU) vulnerability by winning a race condition when Kaseya V... |
| CVE-2017-18249 | — | — | 0.3% | Mar 26, 2018 | The add_free_nid function in fs/f2fs/node.c in the Linux kernel before 4.12 does not properly track an allocated nid, wh... |
| CVE-2017-18248 | — | — | 2.3% | Mar 26, 2018 | The add_job function in scheduler/ipp.c in CUPS before 2.2.6, when D-Bus support is enabled, can be crashed by remote at... |
| CVE-2017-6278 | — | — | 0.3% | Mar 26, 2018 | NVIDIA Tegra kernel contains a vulnerability in the CORE DVFS Thermal driver where there is the potential to read or wri... |
| CVE-2017-15534 | — | — | 0.4% | Mar 26, 2018 | The Norton App Lock prior to version 1.3.0.13 can be susceptible to an authentication bypass exploit. In this type of ci... |
| CVE-2017-15715 | — | — | 86.0% | Mar 26, 2018 | In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a ma... |
| CVE-2017-15710 | — | — | 18.2% | Mar 26, 2018 | In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPChar... |
| CVE-2017-17751 | — | — | 1.0% | Mar 24, 2018 | Bose SoundTouch devices allows remote attackers to achieve remote control via a crafted web site that uses the WebSocket... |
| CVE-2017-17750 | — | — | 0.5% | Mar 24, 2018 | Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify. |
| CVE-2017-17749 | — | — | 0.5% | Mar 24, 2018 | Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora. |
| CVE-2017-18247 | — | — | 1.0% | Mar 23, 2018 | The av_audio_fifo_size function in libavutil/audio_fifo.c in Libav 12.2 allows remote attackers to cause a denial of ser... |
| CVE-2017-18246 | — | — | 1.0% | Mar 23, 2018 | The pcm_encode_frame function in libavcodec/pcm.c in Libav 12.2 allows remote attackers to cause a denial of service (he... |
| CVE-2017-18245 | — | — | 1.4% | Mar 23, 2018 | The mpc8_probe function in libavformat/mpc8.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-b... |
| CVE-2017-1762 | MEDIUM | 5.4 | 1.0% | Mar 23, 2018 | IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 and 6.0) is vulnerable to cross-site scripting.... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now