2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-4940 | MEDIUM | 6.1 | 0.9% | Dec 20, 2017 | The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESX... |
| CVE-2017-17788 | MEDIUM | 5.5 | 1.1% | Dec 20, 2017 | In GIMP 2.8.22, there is a stack-based buffer over-read in xcf_load_stream in app/xcf/xcf.c when there is no '\0' charac... |
| CVE-2017-17780 | MEDIUM | 6.1 | 1.0% | Dec 20, 2017 | The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message ... |
| CVE-2017-16355 | MEDIUM | 4.7 | 0.4% | Dec 14, 2017 | In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Ent... |
| CVE-2017-17669 | MEDIUM | 5.5 | 1.6% | Dec 13, 2017 | There is a heap-based buffer over-read in the Exiv2::Internal::PngChunk::keyTXTChunk function of pngchunk_int.cpp in Exi... |
| CVE-2017-11305 | MEDIUM | 6.5 | 3.6% | Dec 13, 2017 | A regression affecting Adobe Flash Player version 27.0.0.187 (and earlier versions) causes the unintended reset of the g... |
| CVE-2017-4942 | MEDIUM | 4.9 | 1.7% | Dec 13, 2017 | VMware AirWatch Console (AWC) contains a Broken Access Control vulnerability. Successful exploitation of this issue coul... |
| CVE-2017-17506 | MEDIUM | 6.5 | 1.3% | Dec 11, 2017 | In HDF5 1.10.1, there is an out of bounds read vulnerability in the function H5Opline_pline_decode in H5Opline.c in libh... |
| CVE-2017-17504 | MEDIUM | 6.5 | 1.6% | Dec 11, 2017 | ImageMagick before 7.0.7-12 has a coders/png.c Magick_png_read_raw_profile heap-based buffer over-read via a crafted fil... |
| CVE-2017-3738 | MEDIUM | 5.9 | 13.4% | Dec 7, 2017 | There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No... |
| CVE-2017-17381 | MEDIUM | 6.5 | 0.4% | Dec 7, 2017 | The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error a... |
| CVE-2017-13165 | MEDIUM | 5.3 | 0.1% | Dec 6, 2017 | An elevation of privilege vulnerability in the kernel file system. Product: Android. Versions: Android kernel. Android I... |
| CVE-2017-16721 | MEDIUM | 6.1 | 0.9% | Dec 4, 2017 | A Cross-site Scripting issue was discovered in Geovap Reliance SCADA Version 4.7.3 Update 2 and prior. This vulnerabilit... |
| CVE-2017-6679 | MEDIUM | 6.4 | 0.4% | Dec 1, 2017 | The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (... |
| CVE-2017-16611 | MEDIUM | 5.5 | 0.4% | Dec 1, 2017 | In libXfont before 1.5.4 and libXfont2 before 2.0.3, a local attacker can open (but not read) files on the system as roo... |
| CVE-2017-17087 | MEDIUM | 5.5 | 0.4% | Dec 1, 2017 | fileio.c in Vim prior to 8.0.1263 sets the group ownership of a .swp file to the editor's primary group (which may be di... |
| CVE-2017-11285 | MEDIUM | 6.1 | 2.7% | Dec 1, 2017 | Adobe ColdFusion has a cross-site scripting (XSS) vulnerability. This affects Update 4 and earlier versions for ColdFusi... |
| CVE-2017-16951 | MEDIUM | 5.5 | 3.2% | Nov 28, 2017 | Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, o... |
| CVE-2017-14389 | MEDIUM | 6.5 | 0.9% | Nov 28, 2017 | An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all version... |
| CVE-2017-15100 | MEDIUM | 6.1 | 1.1% | Nov 27, 2017 | An attacker submitting facts to the Foreman server containing HTML can cause a stored XSS on certain pages: (1) Facts pa... |
| CVE-2017-8044 | MEDIUM | 6.1 | 0.9% | Nov 27, 2017 | In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow... |
| CVE-2017-8031 | MEDIUM | 5.3 | 1.1% | Nov 27, 2017 | An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior... |
| CVE-2017-6166 | MEDIUM | 5.9 | 1.9% | Nov 22, 2017 | In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some ... |
| CVE-2017-1000236 | MEDIUM | 6.1 | 0.8% | Nov 17, 2017 | I, Librarian version <=4.6 & 4.7 is vulnerable to Reflected Cross-Site Scripting in the temp.php resulting in an attacke... |
| CVE-2017-1000234 | MEDIUM | 5.3 | 1.2% | Nov 17, 2017 | I, Librarian version <=4.6 & 4.7 is vulnerable to Directory Enumeration in the jqueryFileTree.php resulting in attacker ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now