2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-9270 | HIGH | 8.7 | 2.0% | Mar 1, 2018 | In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryp... |
| CVE-2017-9269 | HIGH | 7.7 | 2.3% | Mar 1, 2018 | In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious reposi... |
| CVE-2017-7436 | HIGH | 8.1 | 1.8% | Mar 1, 2018 | In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead ... |
| CVE-2017-7435 | HIGH | 8.1 | 1.8% | Mar 1, 2018 | In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead ... |
| CVE-2017-14798 | HIGH | 7.3 | 1.0% | Mar 1, 2018 | A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escal... |
| CVE-2017-18202 | HIGH | 7 | 0.4% | Feb 27, 2018 | The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which a... |
| CVE-2017-15518 | HIGH | 7.8 | 0.3% | Feb 23, 2018 | All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged da... |
| CVE-2017-14535 | HIGH | 8.8 | 50.1% | Feb 16, 2018 | trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php... |
| CVE-2017-5130 | HIGH | 8.8 | 3.0% | Feb 7, 2018 | An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other pro... |
| CVE-2017-17552 | HIGH | 8.8 | 2.1% | Feb 7, 2018 | /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks vi... |
| CVE-2017-12626 | HIGH | 7.5 | 10.2% | Jan 29, 2018 | Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsin... |
| CVE-2017-18079 | HIGH | 7.8 | 0.4% | Jan 29, 2018 | drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointe... |
| CVE-2017-18078 | HIGH | 7.8 | 1.1% | Jan 29, 2018 | systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the ... |
| CVE-2017-18076 | HIGH | 7.5 | 2.1% | Jan 26, 2018 | In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition ... |
| CVE-2017-18075 | HIGH | 7.8 | 0.4% | Jan 24, 2018 | crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access th... |
| CVE-2017-15108 | HIGH | 7.8 | 0.4% | Jan 20, 2018 | spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local... |
| CVE-2017-12130 | HIGH | 7.5 | 2.3% | Jan 20, 2018 | An exploitable NULL pointer dereference vulnerability exists in the tinysvcmdns library version 2017-11-05. A specially ... |
| CVE-2017-14460 | HIGH | 7.5 | 1.2% | Jan 19, 2018 | An exploitable overly permissive cross-domain (CORS) whitelist vulnerability exists in JSON-RPC of Parity Ethereum clien... |
| CVE-2017-14457 | HIGH | 8.2 | 1.7% | Jan 19, 2018 | An exploitable information leak/denial of service vulnerability exists in the libevm (Ethereum Virtual Machine) `create2... |
| CVE-2017-12119 | HIGH | 7.5 | 2.1% | Jan 19, 2018 | An exploitable unhandled exception vulnerability exists in multiple APIs of CPP-Ethereum JSON-RPC. Specially crafted JSO... |
| CVE-2017-12118 | HIGH | 8.1 | 1.6% | Jan 19, 2018 | An exploitable improper authorization vulnerability exists in miner_stop API of cpp-ethereum's JSON-RPC (commit 4e101574... |
| CVE-2017-12116 | HIGH | 8.1 | 1.7% | Jan 19, 2018 | An exploitable improper authorization vulnerability exists in miner_setGasPrice API of cpp-ethereum's JSON-RPC (commit 4... |
| CVE-2017-12113 | HIGH | 8.1 | 1.5% | Jan 19, 2018 | An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum's JSON-RPC (commit 4e10... |
| CVE-2017-12117 | HIGH | 8.1 | 1.4% | Jan 19, 2018 | An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e10157... |
| CVE-2017-12115 | HIGH | 8.1 | 1.6% | Jan 19, 2018 | An exploitable improper authorization vulnerability exists in miner_setEtherbase API of cpp-ethereum's JSON-RPC (commit ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now