2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2017-8807CRITICAL9.1vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows r...
CVE-2017-5533CRITICAL9.3A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition,...
CVE-2017-3891CRITICAL9.6In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default conf...
CVE-2017-16783CRITICAL9.8In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
CVE-2017-16764CRITICAL9.8An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in dja...
CVE-2017-2922CRITICAL9.8An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. ...
CVE-2017-2921CRITICAL9.8An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. ...
CVE-2017-2894CRITICAL9.8An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6...
CVE-2017-2892CRITICAL9.8An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6...
CVE-2017-2891CRITICAL9.8An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinar...
CVE-2017-2864CRITICAL9.8An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Speci...
CVE-2017-12085CRITICAL9An exploitable routing vulnerability exists in the Circle with Disney cloud infrastructure. A specially crafted packet c...
CVE-2017-16548CRITICAL9.8The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character...
CVE-2017-1000121CRITICAL9.8The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, al...
CVE-2017-1000257CRITICAL9.1An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the dat...
CVE-2017-15990CRITICAL9.8Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
CVE-2017-15982CRITICAL9.8Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editi...
CVE-2017-15981CRITICAL9.8Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for fo...
CVE-2017-15971CRITICAL9.8Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php send...
CVE-2017-5053CRITICAL9.6An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for A...
CVE-2017-15222CRITICAL9.8Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
CVE-2017-10346CRITICAL9.6Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions t...
CVE-2017-10285CRITICAL9.6Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that ...
CVE-2017-15376CRITICAL9.8The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute a...
CVE-2017-12629CRITICAL9.8Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction wi...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now