2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-18235An issue was discovered in Exempi before 2.4.3. The VPXChunk class in XMPFiles/source/FormatSupport/WEBP_Support.cpp doe...
CVE-2017-18234An issue was discovered in Exempi before 2.4.3. It allows remote attackers to cause a denial of service (invalid memcpy ...
CVE-2017-18233An issue was discovered in Exempi before 2.4.4. Integer overflow in the Chunk class in XMPFiles/source/FormatSupport/RIF...
CVE-2017-18232The Serial Attached SCSI (SAS) implementation in the Linux kernel through 4.15.9 mishandles a mutex within libsas, which...
CVE-2017-12194A flaw was found in the way spice-client processed certain messages sent from the server. An attacker, having control of...
CVE-2017-18231An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function Rea...
CVE-2017-18230An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function Rea...
CVE-2017-18229An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFF...
CVE-2017-1741MEDIUM4.3IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information ca...
CVE-2017-16251A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated u...
CVE-2017-16250A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate...
CVE-2017-17442In BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability that cou...
CVE-2017-1002102HIGH7.1In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secre...
CVE-2017-1002101HIGH8.8In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath...
CVE-2017-18228Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet reques...
CVE-2017-2667HIGH8.1Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bind...
CVE-2017-2661ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation ...
CVE-2017-2628curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015...
CVE-2017-2619HIGH7.5Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access ...
CVE-2017-2585Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that ...
CVE-2017-6288NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local informatio...
CVE-2017-6287NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local informatio...
CVE-2017-6286NVIDIA libnvomx contains a possible out of bounds write due to a missing bounds check which could lead to local escalati...
CVE-2017-6285NVIDIA libnvrm contains a possible out of bounds read due to a missing bounds check which could lead to local informatio...
CVE-2017-6281NVIDIA libnvomx contains a possible out of bounds write due to a improper input validation which could lead to local esc...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now