2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-13696A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9...
CVE-2017-12187xorg-x11-server before 1.19.5 was missing length validation in RENDER extension allowing malicious X client to cause X s...
CVE-2017-12186xorg-x11-server before 1.19.5 was missing length validation in X-Resource extension allowing malicious X client to cause...
CVE-2017-12185xorg-x11-server before 1.19.5 was missing length validation in MIT-SCREEN-SAVER extension allowing malicious X client to...
CVE-2017-12184xorg-x11-server before 1.19.5 was missing length validation in XINERAMA extension allowing malicious X client to cause X...
CVE-2017-12183xorg-x11-server before 1.19.5 was missing length validation in XFIXES extension allowing malicious X client to cause X s...
CVE-2017-12182xorg-x11-server before 1.19.5 was missing length validation in XFree86 DRI extension allowing malicious X client to caus...
CVE-2017-12181xorg-x11-server before 1.19.5 was missing length validation in XFree86 DGA extension allowing malicious X client to caus...
CVE-2017-12180xorg-x11-server before 1.19.5 was missing length validation in XFree86 VidModeExtension allowing malicious X client to c...
CVE-2017-12179xorg-x11-server before 1.19.5 was vulnerable to integer overflow in (S)ProcXIBarrierReleasePointer functions allowing ma...
CVE-2017-12178xorg-x11-server before 1.19.5 had wrong extra length check in ProcXIChangeHierarchy function allowing malicious X client...
CVE-2017-12177xorg-x11-server before 1.19.5 was vulnerable to integer overflow in ProcDbeGetVisualInfo function allowing malicious X c...
CVE-2017-12176xorg-x11-server before 1.19.5 was missing extra length validation in ProcEstablishConnection function allowing malicious...
CVE-2017-1769IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute ma...
CVE-2017-15718The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the No...
CVE-2017-1000475FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated ...
CVE-2017-18075HIGH7.8crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access th...
CVE-2017-15697A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause ...
CVE-2017-12632A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix ...
CVE-2017-15531Symantec Reporter 9.5 prior to 9.5.4.1 and 10.1 prior to 10.1.5.5 does not restrict excessive authentication attempts fo...
CVE-2017-18030MEDIUM4.4The cirrus_invalidate_region function in hw/display/cirrus_vga.c in Qemu allows local OS guest privileged users to cause...
CVE-2017-17999SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL comman...
CVE-2017-15513Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-15512Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2017-15511Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now