2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14798 | HIGH | 7.3 | 1.0% | Mar 1, 2018 | A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escal... |
| CVE-2017-6154 | — | — | 1.8% | Mar 1, 2018 | On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, the BIG-IP ASM bd daemon may core dump memor... |
| CVE-2017-6150 | — | — | 1.8% | Mar 1, 2018 | Under certain conditions for F5 BIG-IP systems 13.0.0 or 12.1.0 - 12.1.3.1, using FastL4 profiles, when the Reassemble I... |
| CVE-2017-12627 | — | — | 8.8% | Mar 1, 2018 | In Apache Xerces-C XML Parser library before 3.2.1, processing of external DTD paths can result in a null pointer derefe... |
| CVE-2017-18208 | — | — | 0.5% | Mar 1, 2018 | The madvise_willneed function in mm/madvise.c in the Linux kernel before 4.14.4 allows local users to cause a denial of ... |
| CVE-2017-18207 | — | — | 1.3% | Mar 1, 2018 | The Wave_read._read_fmt_chunk function in Lib/wave.py in Python through 3.6.4 does not ensure a nonzero channel value, w... |
| CVE-2017-9447 | — | — | 2.0% | Feb 28, 2018 | In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improp... |
| CVE-2017-12191 | — | — | 0.9% | Feb 28, 2018 | A flaw was found in the CloudForms account configuration when using VMware. By default, a shared account is used that ha... |
| CVE-2017-18206 | — | — | 3.2% | Feb 27, 2018 | In utils.c in zsh before 5.4, symlink expansion had a buffer overflow. |
| CVE-2017-18205 | — | — | 2.1% | Feb 27, 2018 | In builtin.c in zsh before 5.4, when sh compatibility mode is used, there is a NULL pointer dereference during processin... |
| CVE-2017-15136 | — | — | 1.0% | Feb 27, 2018 | When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the h... |
| CVE-2017-7671 | — | — | 2.3% | Feb 27, 2018 | There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TL... |
| CVE-2017-5660 | — | — | 2.0% | Feb 27, 2018 | There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and lin... |
| CVE-2017-18204 | — | — | 0.5% | Feb 27, 2018 | The ocfs2_setattr function in fs/ocfs2/file.c in the Linux kernel before 4.14.2 allows local users to cause a denial of ... |
| CVE-2017-18203 | — | — | 0.3% | Feb 27, 2018 | The dm_get_from_kobject function in drivers/md/dm.c in the Linux kernel before 4.14.3 allow local users to cause a denia... |
| CVE-2017-12091 | — | — | — | Feb 27, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-14462, CVE-2017-14463, CVE-2017-14464, CVE-2017... |
| CVE-2017-17478 | — | — | 0.5% | Feb 27, 2018 | An XSS issue was discovered in Designer Studio in Pegasystems Pega Platform 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.2, 7.2.1, and... |
| CVE-2017-16770 | — | — | 1.9% | Feb 27, 2018 | File and directory information exposure vulnerability in SYNO.SurveillanceStation.PersonalSettings.Photo in Synology Sur... |
| CVE-2017-16767 | — | — | 1.0% | Feb 27, 2018 | Cross-site scripting (XSS) vulnerability in User Profile in Synology Surveillance Station before 8.1.2-5469 allows remot... |
| CVE-2017-15693 | — | — | 2.6% | Feb 27, 2018 | In Apache Geode before v1.4.0, the Geode server stores application objects in serialized form. Certain cluster operation... |
| CVE-2017-15692 | — | — | 5.1% | Feb 27, 2018 | In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an... |
| CVE-2017-10939 | — | — | — | Feb 27, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2017-10938 | — | — | — | Feb 27, 2018 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2017-18202 | HIGH | 7 | 0.4% | Feb 27, 2018 | The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which a... |
| CVE-2017-16814 | — | — | 1.1% | Feb 26, 2018 | A Directory Traversal issue was discovered in the Foxit MobilePDF app before 6.1 for iOS. This occurs by abusing the URL... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now