2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-15518 | HIGH | 7.8 | 0.3% | Feb 23, 2018 | All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged da... |
| CVE-2017-14910 | — | — | 0.9% | Feb 23, 2018 | In Snapdragon Automobile, Snapdragon IoT and Snapdragon Mobile MDM9206 MDM9607, MDM9650, S820A, S820Am, SD 210/SD 212/SD... |
| CVE-2017-14884 | — | — | 0.2% | Feb 23, 2018 | In all Qualcomm products with Android releases from CAF using the Linux kernel, due to lack of bounds checking on the va... |
| CVE-2017-16769 | — | — | 1.9% | Feb 23, 2018 | Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attacke... |
| CVE-2017-18196 | — | — | 0.4% | Feb 23, 2018 | Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp... |
| CVE-2017-5251 | — | — | 0.5% | Feb 22, 2018 | In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and c... |
| CVE-2017-5250 | — | — | 0.7% | Feb 22, 2018 | In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user a... |
| CVE-2017-5249 | — | — | 0.7% | Feb 22, 2018 | In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize... |
| CVE-2017-18194 | — | — | 1.5% | Feb 22, 2018 | SQL injection vulnerability in users/signup.php in the "signup" component in HamayeshNegar CMS allows a remote attacker ... |
| CVE-2017-18193 | — | — | 0.4% | Feb 22, 2018 | fs/f2fs/extent_cache.c in the Linux kernel before 4.13 mishandles extent trees, which allows local users to cause a deni... |
| CVE-2017-1758 | — | — | 1.7% | Feb 21, 2018 | IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Tra... |
| CVE-2017-1604 | — | — | 0.8% | Feb 21, 2018 | IBM Maximo Anywhere 7.5 and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar... |
| CVE-2017-1462 | — | — | 0.8% | Feb 21, 2018 | IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2017-12161 | — | — | 1.4% | Feb 21, 2018 | It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a ... |
| CVE-2017-14993 | — | — | 1.2% | Feb 20, 2018 | OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11... |
| CVE-2017-12415 | — | — | 0.7% | Feb 20, 2018 | OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10... |
| CVE-2017-17455 | — | — | 0.6% | Feb 20, 2018 | Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in... |
| CVE-2017-17454 | — | — | 0.7% | Feb 20, 2018 | Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerab... |
| CVE-2017-10963 | — | — | 0.9% | Feb 20, 2018 | In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a... |
| CVE-2017-6193 | — | — | 7.8% | Feb 20, 2018 | Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arb... |
| CVE-2017-6192 | — | — | 7.1% | Feb 20, 2018 | Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arb... |
| CVE-2017-16356 | — | — | 2.3% | Feb 20, 2018 | Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScrip... |
| CVE-2017-18192 | — | — | 1.2% | Feb 20, 2018 | smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for A... |
| CVE-2017-16835 | — | — | 0.7% | Feb 20, 2018 | The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, ... |
| CVE-2017-7376 | — | — | 24.1% | Feb 19, 2018 | Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port v... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now