2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2017-14417CRITICAL9.8register_send.php on D-Link DIR-850L REV. B (with firmware through FW208WWb02) devices does not require authentication, ...
CVE-2017-14122CRITICAL9.1unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile...
CVE-2017-14062CRITICAL9.8Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause ...
CVE-2017-12865CRITICAL9.8Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of ser...
CVE-2017-13715CRITICAL9.8The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto...
CVE-2017-13707CRITICAL9.8Privilege escalation in Replibit Backup Manager earlier than version 2017.08.04 allows attackers to gain root privileges...
CVE-2017-12816CRITICAL9.8In Kaspersky Internet Security for Android 11.12.4.1622, some of application exports activities have weak permissions, w...
CVE-2017-11357CRITICAL9.8Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a...
CVE-2017-11317CRITICAL9.8Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload...
CVE-2017-13137CRITICAL9.8The FormCraft Basic plugin 1.0.5 for WordPress has SQL injection in the id parameter to form.php.
CVE-2017-12858CRITICAL9.8Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecifie...
CVE-2017-13139CRITICAL9.8In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, the ReadOneMNGImage function in coders/png.c has an out-of-bounds ...
CVE-2017-12943CRITICAL9.8D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?RE...
CVE-2017-12762CRITICAL9.8In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy wi...
CVE-2017-10111CRITICAL9.6Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). The supported vers...
CVE-2017-10110CRITICAL9.6Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are J...
CVE-2017-10107CRITICAL9.6Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that ...
CVE-2017-10102CRITICAL9Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that ...
CVE-2017-10101CRITICAL9.6Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that...
CVE-2017-10096CRITICAL9.6Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP). Supported versions that...
CVE-2017-10090CRITICAL9.6Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions...
CVE-2017-10089CRITICAL9.6Vulnerability in the Java SE component of Oracle Java SE (subcomponent: ImageIO). Supported versions that are affected a...
CVE-2017-10087CRITICAL9.6Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions...
CVE-2017-10086CRITICAL9.6Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected ar...
CVE-2017-12478CRITICAL9.8It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now