2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-15518HIGH7.8All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged da...
CVE-2017-14910In Snapdragon Automobile, Snapdragon IoT and Snapdragon Mobile MDM9206 MDM9607, MDM9650, S820A, S820Am, SD 210/SD 212/SD...
CVE-2017-14884In all Qualcomm products with Android releases from CAF using the Linux kernel, due to lack of bounds checking on the va...
CVE-2017-16769Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attacke...
CVE-2017-18196Leptonica 1.74.4 constructs unintended pathnames (containing duplicated path components) when operating on files in /tmp...
CVE-2017-5251In version 1012 and prior of Insteon's Insteon Hub, the radio transmissions used for communication between the hub and c...
CVE-2017-5250In version 1.9.7 and prior of Insteon's Insteon for Hub Android app, the OAuth token used by the app to authorize user a...
CVE-2017-5249In version 6.1.0.19 and prior of Wink Labs's Wink - Smart Home Android app, the OAuth token used by the app to authorize...
CVE-2017-18194SQL injection vulnerability in users/signup.php in the "signup" component in HamayeshNegar CMS allows a remote attacker ...
CVE-2017-18193fs/f2fs/extent_cache.c in the Linux kernel before 4.13 mishandles extent trees, which allows local users to cause a deni...
CVE-2017-1758IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Tra...
CVE-2017-1604IBM Maximo Anywhere 7.5 and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrar...
CVE-2017-1462IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja...
CVE-2017-12161It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a ...
CVE-2017-14993OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11...
CVE-2017-12415OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10...
CVE-2017-17455Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in...
CVE-2017-17454Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerab...
CVE-2017-10963In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a...
CVE-2017-6193Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arb...
CVE-2017-6192Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arb...
CVE-2017-16356Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScrip...
CVE-2017-18192smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for A...
CVE-2017-16835The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, ...
CVE-2017-7376Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port v...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now