2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17981 | — | — | 0.5% | Dec 30, 2017 | PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter. |
| CVE-2017-17975 | — | — | 0.4% | Dec 30, 2017 | Use-after-free in the usbtv_probe function in drivers/media/usb/usbtv/usbtv-core.c in the Linux kernel through 4.14.10 a... |
| CVE-2017-17901 | — | — | 2.3% | Dec 29, 2017 | ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets... |
| CVE-2017-17974 | — | — | 1.7% | Dec 29, 2017 | BA SYSTEMS BAS Web on BAS920 devices (with Firmware 01.01.00*, HTTPserv 00002, and Script 02.*) and ISC2000 devices allo... |
| CVE-2017-17973 | HIGH | 8.8 | 3.1% | Dec 29, 2017 | In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a thi... |
| CVE-2017-17910 | — | — | 0.3% | Dec 29, 2017 | On Hoermann BiSecur devices before 2018, a vulnerability can be exploited by recording a single radio transmission. An a... |
| CVE-2017-17971 | — | — | 1.0% | Dec 29, 2017 | The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes bu... |
| CVE-2017-17933 | MEDIUM | 6.1 | 0.9% | Dec 29, 2017 | cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via... |
| CVE-2017-17760 | MEDIUM | 6.5 | 2.2% | Dec 29, 2017 | OpenCV 3.3.1 has a Buffer Overflow in the cv::PxMDecoder::readData function in grfmt_pxm.cpp, because an incorrect size ... |
| CVE-2017-17920 | — | — | 1.5% | Dec 29, 2017 | SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execut... |
| CVE-2017-17919 | HIGH | 8.1 | 1.5% | Dec 29, 2017 | SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute ... |
| CVE-2017-17917 | HIGH | 8.1 | 2.3% | Dec 29, 2017 | SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute ... |
| CVE-2017-17916 | HIGH | 8.1 | 1.5% | Dec 29, 2017 | SQL injection vulnerability in the 'find_by' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execut... |
| CVE-2017-17968 | — | — | 39.4% | Dec 29, 2017 | A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remot... |
| CVE-2017-16876 | — | — | 2.2% | Dec 29, 2017 | Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote att... |
| CVE-2017-17967 | — | — | 0.8% | Dec 28, 2017 | pptreader.dll in Kingsoft WPS Office 10.1.0.6930 allows remote attackers to cause a denial of service via a crafted PPT ... |
| CVE-2017-17960 | — | — | 0.5% | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php. |
| CVE-2017-17959 | — | — | 1.2% | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter. |
| CVE-2017-17958 | — | — | 0.7% | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter. |
| CVE-2017-17957 | — | — | 1.2% | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter. |
| CVE-2017-17956 | — | — | 0.7% | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter. |
| CVE-2017-17955 | — | — | 0.7% | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter. |
| CVE-2017-17954 | — | — | 0.7% | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter. |
| CVE-2017-17953 | — | — | 0.7% | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter. |
| CVE-2017-17952 | — | — | 1.1% | Dec 28, 2017 | PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now