2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2017-4940MEDIUM6.1The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESX...
CVE-2017-17788MEDIUM5.5In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' charac...
CVE-2017-17780MEDIUM6.1The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message ...
CVE-2017-16355MEDIUM4.7In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Ent...
CVE-2017-17669MEDIUM5.5There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp in Exi...
CVE-2017-11305MEDIUM6.5A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the g...
CVE-2017-4942MEDIUM4.9VMware AirWatch Console (AWC) contains a Broken Access Control vulnerability. Successful exploitation of this issue coul...
CVE-2017-17506MEDIUM6.5In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode in H5Opline.c in libh...
CVE-2017-17504MEDIUM6.5ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted fil...
CVE-2017-3738MEDIUM5.9There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No...
CVE-2017-17381MEDIUM6.5The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error a...
CVE-2017-13165MEDIUM5.3An elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android I...
CVE-2017-16721MEDIUM6.1A Cross-site Scripting issue was discovered in Geovap Reliance SCADA Version 4.7.3 Update 2 and prior. This vulnerabilit...
CVE-2017-6679MEDIUM6.4The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (...
CVE-2017-16611MEDIUM5.5In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as roo...
CVE-2017-17087MEDIUM5.5fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be di...
CVE-2017-11285MEDIUM6.1Adobe ColdFusion has a cross-site scripting (XSS) vulnerability. This affects Update 4 and earlier versions for ColdFusi...
CVE-2017-16951MEDIUM5.5Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, o...
CVE-2017-14389MEDIUM6.5An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all version...
CVE-2017-15100MEDIUM6.1An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts pa...
CVE-2017-8044MEDIUM6.1In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow...
CVE-2017-8031MEDIUM5.3An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior...
CVE-2017-6166MEDIUM5.9In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some ...
CVE-2017-1000236MEDIUM6.1I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacke...
CVE-2017-1000234MEDIUM5.3I, Librarian version <=4.6 & 4.7 is vulnerable to Directory Enumeration in the jqueryFileTree.php resulting in attacker ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now