2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-13239A information disclosure vulnerability in the Android framework (ui framework). Product: Android. Versions: 8.0. ID: A-6...
CVE-2017-13238In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical acces...
CVE-2017-13236In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to loc...
CVE-2017-13235A other vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. ID:...
CVE-2017-13234In DLSParser of the sonivox library, there is possible resource exhaustion due to a memory leak. This could lead to remo...
CVE-2017-13233In ihevcd_ctb_boundary_strength_pbslice of libhevc, there is possible resource exhaustion. This could lead to a remote t...
CVE-2017-13232In audioserver, there is an out-of-bounds write due to a log statement using %s with an array that may not be NULL termi...
CVE-2017-13231In libmediadrm, there is an out-of-bounds write due to improper input validation. This could lead to local elevation of ...
CVE-2017-13230In hevc codec, there is an out-of-bounds write due to an incorrect bounds check with the i2_pic_width_in_luma_samples va...
CVE-2017-13229A remote code execution vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1....
CVE-2017-13228In function ih264d_ref_idx_reordering of libavc, there is an out-of-bounds write due to modCount being defined as an uns...
CVE-2017-18179Progress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a passwor...
CVE-2017-18178Authenticate/SWT in Progress Sitefinity 9.1 has an open redirect issue in which an authentication token is sent to the r...
CVE-2017-18177Progress Sitefinity 9.1 has XSS via the Last name, First name, and About fields on the New User Creation Page. This is f...
CVE-2017-18176Progress Sitefinity 9.1 has XSS via file upload, because JavaScript code in an HTML file has the same origin as the appl...
CVE-2017-18175Progress Sitefinity 9.1 has XSS via the Content Management Template Configuration (aka Templateconfiguration), as demons...
CVE-2017-18174In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregist...
CVE-2017-1000510Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in exe...
CVE-2017-1000509Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in executi...
CVE-2017-1000508Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can...
CVE-2017-1000507Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in deni...
CVE-2017-1000506Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result ...
CVE-2017-0911Twitter Kit for iOS versions 3.0 to 3.2.1 is vulnerable to a callback verification flaw in the "Login with Twitter" comp...
CVE-2017-10690In previous versions of Puppet Agent it was possible for the agent to retrieve facts from an environment that it was not...
CVE-2017-10689In previous versions of Puppet Agent it was possible to install a module with world writable permissions. Puppet Agent 5...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now