2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2017-17497HIGH7.5In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentatio...
CVE-2017-16368HIGH8.8An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier ver...
CVE-2017-15868HIGH7.8The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2...
CVE-2017-8824HIGH7.8The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privilege...
CVE-2017-16895HIGH7.8The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper...
CVE-2017-15701HIGH7.5In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame si...
CVE-2017-11286HIGH7.5Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions fo...
CVE-2017-1000405HIGH7The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside...
CVE-2017-17065HIGH7.5An issue was discovered on D-Link DIR-605L Model B before FW2.11betaB06_hbrf devices, related to the code that handles t...
CVE-2017-17058HIGH7.5The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco...
CVE-2017-17053HIGH7The init_new_context function in arch/x86/include/asm/mmu_context.h in the Linux kernel before 4.12.10 does not correctl...
CVE-2017-17052HIGH7.8The mm_init function in kernel/fork.c in the Linux kernel before 4.12.10 does not clear the ->exe_file member of a new p...
CVE-2017-8001HIGH8.4An issue was discovered in EMC ScaleIO 2.0.1.x. In a Linux environment, one of the support scripts saves the credentials...
CVE-2017-15275HIGH7.5Samba before 4.7.3 might allow remote attackers to obtain sensitive information by leveraging failure of the server to c...
CVE-2017-4995HIGH8.1An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. Wh...
CVE-2017-16939HIGH7.8The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gai...
CVE-2017-16932HIGH7.5parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
CVE-2017-16879HIGH7.8Stack-based buffer overflow in the _nc_write_entry function in tinfo/write_entry.c in ncurses 6.0 allows attackers to ca...
CVE-2017-2718HIGH8.8FusionSphere OpenStack with software V100R006C00 and V100R006C10RC2 has two command injection vulnerabilities due to the...
CVE-2017-2704HIGH7.5Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions...
CVE-2017-5729HIGH7.4Frame replay vulnerability in Wi-Fi subsystem in Intel Dual-Band and Tri-Band Wireless-AC Products allows remote attacke...
CVE-2017-5712HIGH7.2Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6...
CVE-2017-5711HIGH7.8Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0...
CVE-2017-2919HIGH7.8An exploitable stack based buffer overflow vulnerability exists in the xls_getfcell function of libxls 1.3.4. A speciall...
CVE-2017-2897HIGH7.8An exploitable out-of-bounds write vulnerability exists in the read_MSAT function of libxls 1.4. A specially crafted XLS...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now