2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-4933 | HIGH | 8.8 | 3.6% | Dec 20, 2017 | VMware ESXi (6.5 before ESXi650-201710401-BG), Workstation (12.x before 12.5.8), and Fusion (8.x before 8.5.9) contain a... |
| CVE-2017-17789 | HIGH | 7.8 | 2.0% | Dec 20, 2017 | In GIMP 2.8.22, there is a heap-based buffer overflow in read_channel_data in plug-ins/common/file-psp.c. |
| CVE-2017-17787 | HIGH | 7.8 | 1.1% | Dec 20, 2017 | In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c. |
| CVE-2017-17786 | HIGH | 7.8 | 1.3% | Dec 20, 2017 | In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.pa... |
| CVE-2017-17785 | HIGH | 7.8 | 1.2% | Dec 20, 2017 | In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c. |
| CVE-2017-17784 | HIGH | 7.8 | 1.5% | Dec 20, 2017 | In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import par... |
| CVE-2017-17763 | HIGH | 7.5 | 1.1% | Dec 19, 2017 | SuperBeam through 4.1.3, when using the LAN or WiFi Direct Share feature, does not use HTTPS or any integrity-protection... |
| CVE-2017-15049 | HIGH | 8.8 | 17.0% | Dec 19, 2017 | The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when c... |
| CVE-2017-15048 | HIGH | 8.8 | 10.2% | Dec 19, 2017 | Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote... |
| CVE-2017-15104 | HIGH | 7.8 | 0.4% | Dec 18, 2017 | An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having lo... |
| CVE-2017-17740 | HIGH | 7.5 | 7.0% | Dec 18, 2017 | contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are ena... |
| CVE-2017-3193 | HIGH | 8.8 | 5.6% | Dec 16, 2017 | Multiple D-Link devices including the DIR-850L firmware versions 1.14B07 and 2.07.B05 contain a stack-based buffer overf... |
| CVE-2017-17712 | HIGH | 7 | 0.3% | Dec 16, 2017 | The raw_sendmsg() function in net/ipv4/raw.c in the Linux kernel through 4.14.6 has a race condition in inet->hdrincl th... |
| CVE-2017-17697 | HIGH | 8.6 | 1.4% | Dec 15, 2017 | The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/... |
| CVE-2017-17530 | HIGH | 8.8 | 1.5% | Dec 14, 2017 | common/help.c in Geomview 1.9.5 does not validate strings before launching the program specified by the BROWSER environm... |
| CVE-2017-17520 | HIGH | 8.8 | 1.9% | Dec 14, 2017 | tools/url_handler.pl in TIN 2.4.1 does not validate strings before launching the program specified by the BROWSER enviro... |
| CVE-2017-17514 | HIGH | 8.8 | 1.7% | Dec 14, 2017 | boxes.c in nip2 8.4.0 does not validate strings before launching the program specified by the BROWSER environment variab... |
| CVE-2017-5534 | HIGH | 8.8 | 1.3% | Dec 13, 2017 | The tibbr user profiles components of tibbr Community, and tibbr Enterprise expose a weakness in an improperly sandboxed... |
| CVE-2017-5530 | HIGH | 8.1 | 0.9% | Dec 13, 2017 | The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may... |
| CVE-2017-14362 | HIGH | 7.3 | 0.5% | Dec 13, 2017 | Cross-Site Request Forgery vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vuln... |
| CVE-2017-14361 | HIGH | 7.4 | 1.0% | Dec 13, 2017 | Man-In-The-Middle vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability... |
| CVE-2017-13099 | HIGH | 7.5 | 24.9% | Dec 13, 2017 | wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange i... |
| CVE-2017-13098 | HIGH | 7.5 | 24.3% | Dec 13, 2017 | BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic ... |
| CVE-2017-17562 | HIGH | 8.1 | 96.3% | Dec 12, 2017 | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T... |
| CVE-2017-2886 | HIGH | 7.8 | 1.0% | Dec 11, 2017 | A memory corruption vulnerability exists in the .PSD parsing functionality of ACDSee Ultimate 10.0.0.292. A specially cr... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now