2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-12112 | HIGH | 8.1 | 1.5% | Jan 19, 2018 | An exploitable improper authorization vulnerability exists in admin_addPeer API of cpp-ethereum's JSON-RPC (commit 4e101... |
| CVE-2017-15126 | HIGH | 8.1 | 4.1% | Jan 14, 2018 | A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handl... |
| CVE-2017-7536 | HIGH | 7 | 0.5% | Jan 10, 2018 | In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflect... |
| CVE-2017-18018 | HIGH | 7.1 | 0.3% | Jan 4, 2018 | In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symli... |
| CVE-2017-1000498 | HIGH | 7.8 | 1.6% | Jan 3, 2018 | AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and po... |
| CVE-2017-1000433 | HIGH | 8.1 | 2.5% | Jan 2, 2018 | pysaml2 version 4.4.0 and older accept any password when run with python optimizations enabled. This allows attackers to... |
| CVE-2017-1000450 | HIGH | 8.8 | 3.2% | Jan 2, 2018 | In opencv/modules/imgcodecs/src/utils.cpp, functions FillUniColor and FillUniGray do not check the input length, which c... |
| CVE-2017-17973 | HIGH | 8.8 | 3.1% | Dec 29, 2017 | In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a thi... |
| CVE-2017-17919 | HIGH | 8.1 | 1.5% | Dec 29, 2017 | SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute ... |
| CVE-2017-17917 | HIGH | 8.1 | 2.3% | Dec 29, 2017 | SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute ... |
| CVE-2017-17916 | HIGH | 8.1 | 1.5% | Dec 29, 2017 | SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execut... |
| CVE-2017-17857 | HIGH | 7.8 | 0.4% | Dec 27, 2017 | The check_stack_boundary function in kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to caus... |
| CVE-2017-17856 | HIGH | 7.8 | 0.4% | Dec 27, 2017 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrupt... |
| CVE-2017-17855 | HIGH | 7.8 | 0.4% | Dec 27, 2017 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrupt... |
| CVE-2017-17854 | HIGH | 7.8 | 0.4% | Dec 27, 2017 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (integer overfl... |
| CVE-2017-17853 | HIGH | 7.8 | 0.4% | Dec 27, 2017 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrupt... |
| CVE-2017-17852 | HIGH | 7.8 | 0.4% | Dec 27, 2017 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrupt... |
| CVE-2017-16996 | HIGH | 7.8 | 0.4% | Dec 27, 2017 | kernel/bpf/verifier.c in the Linux kernel through 4.14.8 allows local users to cause a denial of service (memory corrupt... |
| CVE-2017-16995 | HIGH | 7.8 | 30.1% | Dec 27, 2017 | The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial ... |
| CVE-2017-12741 | HIGH | 7.5 | 3.3% | Dec 26, 2017 | Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be r... |
| CVE-2017-12736 | HIGH | 8.8 | 1.0% | Dec 26, 2017 | After initial configuration, the Ruggedcom Discovery Protocol (RCDP) is still able to write to the device under certain ... |
| CVE-2017-10868 | HIGH | 7.5 | 3.5% | Dec 22, 2017 | H2O version 2.2.2 and earlier allows remote attackers to cause a denial of service in the server via specially crafted H... |
| CVE-2017-17806 | HIGH | 7.8 | 0.6% | Dec 20, 2017 | The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptogr... |
| CVE-2017-17805 | HIGH | 7.8 | 0.4% | Dec 20, 2017 | The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowin... |
| CVE-2017-4941 | HIGH | 8.8 | 3.2% | Dec 20, 2017 | VMware ESXi (6.0 before ESXi600-201711101-SG, 5.5 ESXi550-201709101-SG), Workstation (12.x before 12.5.8), and Fusion (8... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now