2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-18034 | — | — | 0.6% | Feb 2, 2018 | The source browse resource in Atlassian Fisheye and Crucible before version 4.5.1 and 4.6.0 allows allows remote attacke... |
| CVE-2017-14180 | — | — | 0.4% | Feb 2, 2018 | Apport 2.13 through 2.20.7 does not properly handle crashes originating from a PID namespace allowing local users to cre... |
| CVE-2017-14179 | — | — | 0.4% | Feb 2, 2018 | Apport before 2.13 does not properly handle crashes originating from a PID namespace allowing local users to create cert... |
| CVE-2017-14178 | — | — | 1.8% | Feb 2, 2018 | In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and theref... |
| CVE-2017-14177 | — | — | 0.4% | Feb 2, 2018 | Apport through 2.20.7 does not properly handle core dumps from setuid binaries allowing local users to create certain fi... |
| CVE-2017-18120 | — | — | 1.8% | Feb 2, 2018 | A double-free bug in the read_gif function in gifread.c in gifsicle 1.90 allows a remote attacker to cause a denial-of-s... |
| CVE-2017-2297 | — | — | 0.6% | Feb 1, 2018 | Puppet Enterprise versions prior to 2016.4.5 and 2017.2.1 did not correctly authenticate users before returning labeled ... |
| CVE-2017-2296 | — | — | 0.9% | Feb 1, 2018 | In Puppet Enterprise 2017.1.x and 2017.2.1, using specially formatted strings with certain formatting characters as Clas... |
| CVE-2017-2293 | — | — | 0.7% | Feb 1, 2018 | Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 shipped with an MCollective configuration that allowed the p... |
| CVE-2017-3160 | — | — | 3.8% | Feb 1, 2018 | After the Android platform is added to Cordova the first time, or after a project is created using the build scripts, th... |
| CVE-2017-16861 | — | — | 2.0% | Feb 1, 2018 | It was possible for double OGNL evaluation in certain redirect action and in WebWork URL and Anchor tags in JSP files to... |
| CVE-2017-1000409 | — | — | 1.2% | Feb 1, 2018 | A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ... |
| CVE-2017-1000408 | — | — | 1.5% | Feb 1, 2018 | A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme... |
| CVE-2017-16914 | — | — | 4.5% | Jan 31, 2018 | The "stub_send_ret_submit()" function (drivers/usb/usbip/stub_tx.c) in the Linux Kernel before version 4.14.8, 4.9.71, 4... |
| CVE-2017-16913 | — | — | 4.0% | Jan 31, 2018 | The "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, a... |
| CVE-2017-16912 | — | — | 4.2% | Jan 31, 2018 | The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 a... |
| CVE-2017-16911 | — | — | 0.4% | Jan 31, 2018 | The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kern... |
| CVE-2017-18043 | — | — | 0.5% | Jan 31, 2018 | Integer overflow in the macro ROUND_UP (n, d) in Quick Emulator (Qemu) allows a user to cause a denial of service (Qemu ... |
| CVE-2017-16945 | — | — | 1.0% | Jan 31, 2018 | The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequen... |
| CVE-2017-16928 | — | — | 1.0% | Jan 31, 2018 | The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently g... |
| CVE-2017-15656 | — | — | 1.5% | Jan 31, 2018 | Password are stored in plaintext in nvram in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asus... |
| CVE-2017-15655 | — | — | 3.1% | Jan 31, 2018 | Multiple buffer overflow vulnerabilities exist in the HTTPd server in Asus asuswrt version <=3.0.0.4.376.X. All have bee... |
| CVE-2017-15654 | — | — | 2.2% | Jan 31, 2018 | Highly predictable session tokens in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) of Asus asuswrt allo... |
| CVE-2017-15653 | — | — | 2.0% | Jan 31, 2018 | Improper administrator IP validation after his login in the HTTPd server in all current versions (<= 3.0.0.4.380.7743) o... |
| CVE-2017-8916 | — | — | 0.3% | Jan 31, 2018 | In Center for Internet Security CIS-CAT Pro Dashboard before 1.0.4, an authenticated user is able to change an administr... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now