2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7500 | HIGH | 7.3 | 0.4% | Aug 13, 2018 | It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directo... |
| CVE-2017-16252 | HIGH | 8.1 | 1.2% | Aug 6, 2018 | Specially crafted commands sent through the PubNub service in Insteon Hub 2245-222 with firmware version 1012 can cause ... |
| CVE-2017-14447 | HIGH | 8.5 | 1.1% | Aug 6, 2018 | An exploitable buffer overflow vulnerability exists in the PubNub message handler for the 'ad' channel of Insteon Hub ru... |
| CVE-2017-16349 | HIGH | 8.1 | 1.2% | Aug 2, 2018 | An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted X... |
| CVE-2017-9118 | HIGH | 7.5 | 3.0% | Aug 2, 2018 | PHP 7.1.5 has an Out of bounds access in php_pcre_replace_impl via a crafted preg_replace call. |
| CVE-2017-7482 | HIGH | 7.8 | 0.5% | Jul 30, 2018 | In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the si... |
| CVE-2017-15118 | HIGH | 8.3 | 11.9% | Jul 27, 2018 | A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client... |
| CVE-2017-2663 | HIGH | 8.2 | 0.4% | Jul 27, 2018 | It was found that subscription-manager's DBus interface before 1.19.4 let unprivileged user access the com.redhat.RHSM1.... |
| CVE-2017-15101 | HIGH | 7.8 | 1.5% | Jul 27, 2018 | A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. ... |
| CVE-2017-2634 | HIGH | 7.5 | 5.2% | Jul 27, 2018 | It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used th... |
| CVE-2017-2646 | HIGH | 7.5 | 1.9% | Jul 27, 2018 | It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, t... |
| CVE-2017-2640 | HIGH | 7.5 | 6.3% | Jul 27, 2018 | An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server c... |
| CVE-2017-2590 | HIGH | 8.1 | 1.3% | Jul 27, 2018 | A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the... |
| CVE-2017-15113 | HIGH | 7.2 | 1.2% | Jul 27, 2018 | ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only... |
| CVE-2017-12148 | HIGH | 8.4 | 1.7% | Jul 27, 2018 | A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repo... |
| CVE-2017-2670 | HIGH | 7.5 | 3.7% | Jul 27, 2018 | It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on ev... |
| CVE-2017-2595 | HIGH | 7.7 | 3.1% | Jul 27, 2018 | It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to auth... |
| CVE-2017-15120 | HIGH | 7.5 | 51.8% | Jul 27, 2018 | An issue has been found in the parsing of authoritative answers in PowerDNS Recursor before 4.0.8, leading to a NULL poi... |
| CVE-2017-7464 | HIGH | 8.7 | 1.9% | Jul 27, 2018 | It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE fla... |
| CVE-2017-12151 | HIGH | 7.4 | 4.6% | Jul 27, 2018 | A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max ... |
| CVE-2017-12150 | HIGH | 7.4 | 13.2% | Jul 26, 2018 | It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when ce... |
| CVE-2017-2589 | HIGH | 8.7 | 0.9% | Jul 26, 2018 | It was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cook... |
| CVE-2017-7530 | HIGH | 8.8 | 1.7% | Jul 26, 2018 | In CloudForms Management Engine (cfme) before 5.7.3 and 5.8.x before 5.8.1, it was found that privilege check is missing... |
| CVE-2017-3209 | HIGH | 8.1 | 1.2% | Jul 24, 2018 | The DBPOWER U818A WIFI quadcopter drone provides FTP access over its own local access point, and allows full file permis... |
| CVE-2017-7467 | HIGH | 7 | 2.8% | Jul 11, 2018 | A buffer overflow flaw was found in the way minicom before version 2.7.1 handled VT100 escape sequences. A malicious ter... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now