2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2017-12112HIGH8.1An exploitable improper authorization vulnerability exists in admin_addPeer API of cpp-ethereum's JSON-RPC (commit 4e101...
CVE-2017-15126HIGH8.1A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handl...
CVE-2017-7536HIGH7In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflect...
CVE-2017-18018HIGH7.1In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symli...
CVE-2017-1000498HIGH7.8AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and po...
CVE-2017-1000433HIGH8.1pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to...
CVE-2017-1000450HIGH8.8In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which c...
CVE-2017-17973HIGH8.8In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a thi...
CVE-2017-17919HIGH8.1SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute ...
CVE-2017-17917HIGH8.1SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute ...
CVE-2017-17916HIGH8.1SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execut...
CVE-2017-17857HIGH7.8The check_stack_boundary function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to caus...
CVE-2017-17856HIGH7.8kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrupt...
CVE-2017-17855HIGH7.8kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrupt...
CVE-2017-17854HIGH7.8kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overfl...
CVE-2017-17853HIGH7.8kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrupt...
CVE-2017-17852HIGH7.8kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrupt...
CVE-2017-16996HIGH7.8kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrupt...
CVE-2017-16995HIGH7.8The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial ...
CVE-2017-12741HIGH7.5Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be r...
CVE-2017-12736HIGH8.8After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain ...
CVE-2017-10868HIGH7.5H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted H...
CVE-2017-17806HIGH7.8The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptogr...
CVE-2017-17805HIGH7.8The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowin...
CVE-2017-4941HIGH8.8VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now