2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-18034The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attacke...
CVE-2017-14180Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to cre...
CVE-2017-14179Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create cert...
CVE-2017-14178In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and theref...
CVE-2017-14177Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain fi...
CVE-2017-18120A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-s...
CVE-2017-2297Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled ...
CVE-2017-2296In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Clas...
CVE-2017-2293Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuration that allowed the p...
CVE-2017-3160After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, th...
CVE-2017-16861It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to...
CVE-2017-1000409A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ...
CVE-2017-1000408A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme...
CVE-2017-16914The "stub_send_ret_submit()" function (drivers/usb/usbip/stub_tx.c) in the Linux Kernel before version 4.14.8, 4.9.71, 4...
CVE-2017-16913The "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, a...
CVE-2017-16912The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 a...
CVE-2017-16911The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kern...
CVE-2017-18043Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu ...
CVE-2017-16945The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequen...
CVE-2017-16928The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently g...
CVE-2017-15656Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asus...
CVE-2017-15655Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have bee...
CVE-2017-15654Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allo...
CVE-2017-15653Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) o...
CVE-2017-8916In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administr...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now