2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8807 | CRITICAL | 9.1 | 4.1% | Nov 16, 2017 | vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows r... |
| CVE-2017-5533 | CRITICAL | 9.3 | 2.0% | Nov 15, 2017 | A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition,... |
| CVE-2017-3891 | CRITICAL | 9.6 | 1.3% | Nov 14, 2017 | In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an elevation of privilege vulnerability in the default conf... |
| CVE-2017-16783 | CRITICAL | 9.8 | 8.0% | Nov 10, 2017 | In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter. |
| CVE-2017-16764 | CRITICAL | 9.8 | 3.1% | Nov 10, 2017 | An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in dja... |
| CVE-2017-2922 | CRITICAL | 9.8 | 2.6% | Nov 7, 2017 | An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. ... |
| CVE-2017-2921 | CRITICAL | 9.8 | 2.4% | Nov 7, 2017 | An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. ... |
| CVE-2017-2894 | CRITICAL | 9.8 | 31.0% | Nov 7, 2017 | An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6... |
| CVE-2017-2892 | CRITICAL | 9.8 | 2.4% | Nov 7, 2017 | An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6... |
| CVE-2017-2891 | CRITICAL | 9.8 | 2.8% | Nov 7, 2017 | An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinar... |
| CVE-2017-2864 | CRITICAL | 9.8 | 1.5% | Nov 7, 2017 | An exploitable vulnerability exists in the generation of authentication token functionality of Circle with Disney. Speci... |
| CVE-2017-12085 | CRITICAL | 9 | 1.7% | Nov 7, 2017 | An exploitable routing vulnerability exists in the Circle with Disney cloud infrastructure. A specially crafted packet c... |
| CVE-2017-16548 | CRITICAL | 9.8 | 5.2% | Nov 6, 2017 | The receive_xattr function in xattrs.c in rsync 3.1.2 and 3.1.3-development does not check for a trailing '\0' character... |
| CVE-2017-1000121 | CRITICAL | 9.8 | 1.2% | Nov 1, 2017 | The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate message size metadata, al... |
| CVE-2017-1000257 | CRITICAL | 9.1 | 6.2% | Oct 31, 2017 | An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the dat... |
| CVE-2017-15990 | CRITICAL | 9.8 | 7.7% | Oct 31, 2017 | Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/. |
| CVE-2017-15982 | CRITICAL | 9.8 | 2.6% | Oct 31, 2017 | Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editi... |
| CVE-2017-15981 | CRITICAL | 9.8 | 2.6% | Oct 31, 2017 | Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for fo... |
| CVE-2017-15971 | CRITICAL | 9.8 | 2.0% | Oct 29, 2017 | Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php send... |
| CVE-2017-5053 | CRITICAL | 9.6 | 2.6% | Oct 27, 2017 | An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for A... |
| CVE-2017-15222 | CRITICAL | 9.8 | 60.3% | Oct 24, 2017 | Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code. |
| CVE-2017-10346 | CRITICAL | 9.6 | 3.0% | Oct 19, 2017 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions t... |
| CVE-2017-10285 | CRITICAL | 9.6 | 3.1% | Oct 19, 2017 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that ... |
| CVE-2017-15376 | CRITICAL | 9.8 | 3.8% | Oct 16, 2017 | The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute a... |
| CVE-2017-12629 | CRITICAL | 9.8 | 91.9% | Oct 14, 2017 | Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction wi... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now