2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-2896 | HIGH | 7.8 | 2.1% | Nov 20, 2017 | An exploitable out-of-bounds write vulnerability exists in the xls_mergedCells function of libxls 1.4. . A specially cra... |
| CVE-2017-12111 | HIGH | 8.8 | 2.1% | Nov 20, 2017 | An exploitable out-of-bounds vulnerability exists in the xls_addCell function of libxls 1.4. A specially crafted XLS fil... |
| CVE-2017-12110 | HIGH | 8.8 | 2.1% | Nov 20, 2017 | An exploitable integer overflow vulnerability exists in the xls_appendSST function of libxls 1.4.A specially crafted XLS... |
| CVE-2017-12608 | HIGH | 7.8 | 2.9% | Nov 20, 2017 | A vulnerability in Apache OpenOffice Writer DOC file parser before 4.1.4, and specifically in ImportOldFormatStyles, all... |
| CVE-2017-12607 | HIGH | 7.8 | 2.6% | Nov 20, 2017 | A vulnerability in OpenOffice's PPT file parser before 4.1.4, and specifically in PPTStyleSheet, allows attackers to cra... |
| CVE-2017-9806 | HIGH | 7.8 | 1.8% | Nov 20, 2017 | A vulnerability in the OpenOffice Writer DOC file parser before 4.1.4, and specifically in the WW8Fonts Constructor, all... |
| CVE-2017-16544 | HIGH | 8.8 | 6.2% | Nov 20, 2017 | In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used... |
| CVE-2017-1000170 | HIGH | 7.5 | 57.6% | Nov 17, 2017 | jqueryFileTree 2.1.5 and older Directory Traversal |
| CVE-2017-16715 | HIGH | 8.6 | 1.3% | Nov 16, 2017 | An Information Exposure issue was discovered in Moxa NPort 5110 Version 2.2, NPort 5110 Version 2.4, NPort 5110 Version ... |
| CVE-2017-15115 | HIGH | 7.8 | 0.5% | Nov 15, 2017 | The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended ne... |
| CVE-2017-15288 | HIGH | 7.8 | 0.4% | Nov 15, 2017 | The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for... |
| CVE-2017-11882 | HIGH | 7.8 | 99.9% | Nov 15, 2017 | Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi... |
| CVE-2017-11878 | HIGH | 7.8 | 6.2% | Nov 15, 2017 | Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft... |
| CVE-2017-16651 | HIGH | 7.8 | 42.8% | Nov 9, 2017 | Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file... |
| CVE-2017-16659 | HIGH | 7.8 | 0.8% | Nov 8, 2017 | The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access t... |
| CVE-2017-2917 | HIGH | 8.8 | 3.2% | Nov 7, 2017 | An exploitable vulnerability exists in the notifications functionality of Circle with Disney running firmware 2.0.1. Spe... |
| CVE-2017-2916 | HIGH | 8.8 | 2.3% | Nov 7, 2017 | An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.... |
| CVE-2017-2915 | HIGH | 8 | 1.4% | Nov 7, 2017 | An exploitable vulnerability exists in the WiFi configuration functionality of Circle with Disney running firmware 2.0.1... |
| CVE-2017-2914 | HIGH | 8.1 | 1.6% | Nov 7, 2017 | An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1... |
| CVE-2017-2909 | HIGH | 7.5 | 1.4% | Nov 7, 2017 | An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially c... |
| CVE-2017-2898 | HIGH | 7.5 | 1.6% | Nov 7, 2017 | An exploitable vulnerability exists in the signature verification of the firmware update functionality of Circle with Di... |
| CVE-2017-2895 | HIGH | 8.2 | 1.3% | Nov 7, 2017 | An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6... |
| CVE-2017-2893 | HIGH | 7.5 | 26.6% | Nov 7, 2017 | An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoos... |
| CVE-2017-2890 | HIGH | 8.8 | 2.6% | Nov 7, 2017 | An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.... |
| CVE-2017-2889 | HIGH | 7.5 | 1.5% | Nov 7, 2017 | An exploitable Denial of Service vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1. A ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now