2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-14458 | HIGH | 8.8 | 3.5% | Apr 23, 2018 | An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version... |
| CVE-2017-2871 | HIGH | 8.8 | 1.1% | Apr 17, 2018 | Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application ... |
| CVE-2017-0358 | HIGH | 7.8 | 2.3% | Apr 13, 2018 | Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environm... |
| CVE-2017-12090 | HIGH | 7.7 | 3.6% | Apr 5, 2018 | An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Microl... |
| CVE-2017-12089 | HIGH | 8.6 | 5.1% | Apr 5, 2018 | An exploitable denial of service vulnerability exists in the program download functionality of Allen Bradley Micrologix ... |
| CVE-2017-12088 | HIGH | 8.6 | 4.5% | Apr 5, 2018 | An exploitable denial of service vulnerability exists in the Ethernet functionality of the Allen Bradley Micrologix 1400... |
| CVE-2017-2861 | HIGH | 7.5 | 1.4% | Apr 5, 2018 | An exploitable Denial of Service vulnerability exists in the use of a return value in the NewProducerStream command in N... |
| CVE-2017-3971 | HIGH | 8.2 | 0.3% | Apr 4, 2018 | Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows at... |
| CVE-2017-3969 | HIGH | 8.2 | 0.8% | Apr 4, 2018 | Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42.... |
| CVE-2017-3965 | HIGH | 8.8 | 0.5% | Apr 4, 2018 | Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Man... |
| CVE-2017-3972 | HIGH | 8.3 | 1.5% | Apr 3, 2018 | Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before... |
| CVE-2017-11509 | HIGH | 8.8 | 6.2% | Mar 28, 2018 | An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing... |
| CVE-2017-0935 | HIGH | 8.8 | 1.3% | Mar 22, 2018 | Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the... |
| CVE-2017-1677 | HIGH | 7.4 | 0.7% | Mar 22, 2018 | IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes th... |
| CVE-2017-1002102 | HIGH | 7.1 | 1.0% | Mar 13, 2018 | In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secre... |
| CVE-2017-1002101 | HIGH | 8.8 | 11.6% | Mar 13, 2018 | In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath... |
| CVE-2017-2667 | HIGH | 8.1 | 0.7% | Mar 12, 2018 | Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bind... |
| CVE-2017-2619 | HIGH | 7.5 | 11.2% | Mar 12, 2018 | Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access ... |
| CVE-2017-12174 | HIGH | 7.5 | 6.0% | Mar 7, 2018 | It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge b... |
| CVE-2017-11649 | HIGH | 8.8 | 0.7% | Mar 7, 2018 | Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allo... |
| CVE-2017-18218 | HIGH | 7.8 | 0.4% | Mar 5, 2018 | In drivers/net/ethernet/hisilicon/hns/hns_enet.c in the Linux kernel before 4.13, local users can cause a denial of serv... |
| CVE-2017-18214 | HIGH | 7.5 | 3.7% | Mar 4, 2018 | The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string... |
| CVE-2017-7429 | HIGH | 8.8 | 0.9% | Mar 2, 2018 | The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code ... |
| CVE-2017-9286 | HIGH | 7.8 | 1.2% | Mar 1, 2018 | The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts runnin... |
| CVE-2017-9274 | HIGH | 7.8 | 2.3% | Mar 1, 2018 | A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager w... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now