2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2017-14458HIGH8.8An exploitable use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version...
CVE-2017-2871HIGH8.8Insufficient security checks exist in the recovery procedure used by the Foscam C1 Indoor HD Camera running application ...
CVE-2017-0358HIGH7.8Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environm...
CVE-2017-12090HIGH7.7An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Microl...
CVE-2017-12089HIGH8.6An exploitable denial of service vulnerability exists in the program download functionality of Allen Bradley Micrologix ...
CVE-2017-12088HIGH8.6An exploitable denial of service vulnerability exists in the Ethernet functionality of the Allen Bradley Micrologix 1400...
CVE-2017-2861HIGH7.5An exploitable Denial of Service vulnerability exists in the use of a return value in the NewProducerStream command in N...
CVE-2017-3971HIGH8.2Cryptanalysis vulnerability in the web interface in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows at...
CVE-2017-3969HIGH8.2Abuse of communication channels vulnerability in the server in McAfee Network Security Management (NSM) before 8.2.7.42....
CVE-2017-3965HIGH8.8Cross-Site Request Forgery (CSRF) (aka Session Riding) vulnerability in the web interface in McAfee Network Security Man...
CVE-2017-3972HIGH8.3Infrastructure-based foot printing vulnerability in the web interface in McAfee Network Security Management (NSM) before...
CVE-2017-11509HIGH8.8An authenticated remote attacker can execute arbitrary code in Firebird SQL Server versions 2.5.7 and 3.0.2 by executing...
CVE-2017-0935HIGH8.8Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the...
CVE-2017-1677HIGH7.4IBM Data Server Driver for JDBC and SQLJ (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) deserializes th...
CVE-2017-1002102HIGH7.1In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secre...
CVE-2017-1002101HIGH8.8In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath...
CVE-2017-2667HIGH8.1Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bind...
CVE-2017-2619HIGH7.5Samba before versions 4.6.1, 4.5.7 and 4.4.11 are vulnerable to a malicious client using a symlink race to allow access ...
CVE-2017-12174HIGH7.5It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge b...
CVE-2017-11649HIGH8.8Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allo...
CVE-2017-18218HIGH7.8In drivers/net/ethernet/hisilicon/hns/hns_enet.c in the Linux kernel before 4.13, local users can cause a denial of serv...
CVE-2017-18214HIGH7.5The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string...
CVE-2017-7429HIGH8.8The certificate upload in NetIQ eDirectory PKI plugin before 8.8.8 Patch 10 Hotfix 1 could be abused to upload JSP code ...
CVE-2017-9286HIGH7.8The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts runnin...
CVE-2017-9274HIGH7.8A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager w...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now