2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2017-9270HIGH8.7In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryp...
CVE-2017-9269HIGH7.7In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious reposi...
CVE-2017-7436HIGH8.1In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead ...
CVE-2017-7435HIGH8.1In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead ...
CVE-2017-14798HIGH7.3A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escal...
CVE-2017-18202HIGH7The __oom_reap_task_mm function in mm/oom_kill.c in the Linux kernel before 4.14.4 mishandles gather operations, which a...
CVE-2017-15518HIGH7.8All versions of OnCommand API Services prior to 2.1 and NetApp Service Level Manager prior to 1.0RC4 log a privileged da...
CVE-2017-14535HIGH8.8trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php...
CVE-2017-5130HIGH8.8An integer overflow in xmlmemory.c in libxml2 before 2.9.5, as used in Google Chrome prior to 62.0.3202.62 and other pro...
CVE-2017-17552HIGH8.8/LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks vi...
CVE-2017-12626HIGH7.5Apache POI in versions prior to release 3.17 are vulnerable to Denial of Service Attacks: 1) Infinite Loops while parsin...
CVE-2017-18079HIGH7.8drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointe...
CVE-2017-18078HIGH7.8systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the ...
CVE-2017-18076HIGH7.5In strategy.rb in OmniAuth before 1.3.2, the authenticity_token value is improperly protected because POST (in addition ...
CVE-2017-18075HIGH7.8crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access th...
CVE-2017-15108HIGH7.8spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local...
CVE-2017-12130HIGH7.5An exploitable NULL pointer dereference vulnerability exists in the tinysvcmdns library version 2017-11-05. A specially ...
CVE-2017-14460HIGH7.5An exploitable overly permissive cross-domain (CORS) whitelist vulnerability exists in JSON-RPC of Parity Ethereum clien...
CVE-2017-14457HIGH8.2An exploitable information leak/denial of service vulnerability exists in the libevm (Ethereum Virtual Machine) `create2...
CVE-2017-12119HIGH7.5An exploitable unhandled exception vulnerability exists in multiple APIs of CPP-Ethereum JSON-RPC. Specially crafted JSO...
CVE-2017-12118HIGH8.1An exploitable improper authorization vulnerability exists in miner_stop API of cpp-ethereum's JSON-RPC (commit 4e101574...
CVE-2017-12116HIGH8.1An exploitable improper authorization vulnerability exists in miner_setGasPrice API of cpp-ethereum's JSON-RPC (commit 4...
CVE-2017-12113HIGH8.1An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum's JSON-RPC (commit 4e10...
CVE-2017-12117HIGH8.1An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's JSON-RPC (commit 4e10157...
CVE-2017-12115HIGH8.1An exploitable improper authorization vulnerability exists in miner_setEtherbase API of cpp-ethereum's JSON-RPC (commit ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now