2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-14798HIGH7.3A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escal...
CVE-2017-6154On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, the BIG-IP ASM bd daemon may core dump memor...
CVE-2017-6150Under certain conditions for F5 BIG-IP systems 13.0.0 or 12.1.0 - 12.1.3.1, using FastL4 profiles, when the Reassemble I...
CVE-2017-12627In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer derefe...
CVE-2017-18208The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of ...
CVE-2017-18207The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, w...
CVE-2017-9447In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improp...
CVE-2017-12191A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that ha...
CVE-2017-18206In utils.c in zsh before 5.4, symlink expansion had a buffer overflow.
CVE-2017-18205In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processin...
CVE-2017-15136When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the h...
CVE-2017-7671There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TL...
CVE-2017-5660There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and lin...
CVE-2017-18204The ocfs2_setattr function in fs/ocfs2/file.c in the Linux kernel before 4.14.2 allows local users to cause a denial of ...
CVE-2017-18203The dm_get_from_kobject function in drivers/md/dm.c in the Linux kernel before 4.14.3 allow local users to cause a denia...
CVE-2017-12091Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-14462, CVE-2017-14463, CVE-2017-14464, CVE-2017...
CVE-2017-17478An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and...
CVE-2017-16770File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Sur...
CVE-2017-16767Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remot...
CVE-2017-15693In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operation...
CVE-2017-15692In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an...
CVE-2017-10939Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-10938Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2017-18202HIGH7The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which a...
CVE-2017-16814A Directory Traversal issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs by abusing the URL...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now