2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-10293 | MEDIUM | 6.1 | 1.5% | Oct 19, 2017 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Javadoc). Supported versions that are affected a... |
| CVE-2017-10286 | MEDIUM | 4.4 | 2.5% | Oct 19, 2017 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are ... |
| CVE-2017-10281 | MEDIUM | 5.3 | 3.3% | Oct 19, 2017 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Suppo... |
| CVE-2017-10274 | MEDIUM | 6.8 | 2.6% | Oct 19, 2017 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affe... |
| CVE-2017-10268 | MEDIUM | 4.1 | 0.7% | Oct 19, 2017 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that... |
| CVE-2017-13083 | MEDIUM | 5.3 | 1.0% | Oct 18, 2017 | Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over H... |
| CVE-2017-15289 | MEDIUM | 6 | 0.5% | Oct 16, 2017 | The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial... |
| CVE-2017-10621 | MEDIUM | 5.3 | 1.8% | Oct 13, 2017 | A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unauthenticated attacker... |
| CVE-2017-10618 | MEDIUM | 5.9 | 1.5% | Oct 13, 2017 | When the 'bgp-error-tolerance' feature â€" designed to help mitigate remote session resets from malformed path... |
| CVE-2017-10617 | MEDIUM | 5 | 2.3% | Oct 13, 2017 | The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an atta... |
| CVE-2017-10616 | MEDIUM | 5.3 | 1.3% | Oct 13, 2017 | The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected relea... |
| CVE-2017-10614 | MEDIUM | 5.3 | 1.7% | Oct 13, 2017 | A vulnerability in telnetd service on Junos OS allows a remote attacker to cause a limited memory and/or CPU consumption... |
| CVE-2017-10613 | MEDIUM | 5.5 | 0.3% | Oct 13, 2017 | A vulnerability in a specific loopback filter action command, processed in a specific logical order of operation, in a r... |
| CVE-2017-10611 | MEDIUM | 6.5 | 0.9% | Oct 13, 2017 | If extended statistics are enabled via 'set chassis extended-statistics', when executing any operation that fetches inte... |
| CVE-2017-10606 | MEDIUM | 4.4 | 0.3% | Oct 13, 2017 | Version 4.40 of the TPM (Trusted Platform Module) firmware on Juniper Networks SRX300 Series has a weakness in generatin... |
| CVE-2017-7352 | MEDIUM | 5.4 | 0.6% | Oct 11, 2017 | Stored Cross-site scripting (XSS) vulnerability in Pure Storage Purity 4.7.5 allows remote authenticated users to inject... |
| CVE-2017-15046 | MEDIUM | 5.5 | 0.7% | Oct 6, 2017 | LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend... |
| CVE-2017-15018 | MEDIUM | 5.5 | 0.8% | Oct 5, 2017 | LAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handl... |
| CVE-2017-1000101 | MEDIUM | 6.5 | 3.9% | Oct 5, 2017 | curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers... |
| CVE-2017-1000100 | MEDIUM | 6.5 | 4.0% | Oct 5, 2017 | When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 by... |
| CVE-2017-14955 | MEDIUM | 5.9 | 12.1% | Oct 2, 2017 | Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, whi... |
| CVE-2017-14928 | MEDIUM | 5.5 | 0.7% | Sep 30, 2017 | In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a c... |
| CVE-2017-14926 | MEDIUM | 5.5 | 0.7% | Sep 30, 2017 | In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF d... |
| CVE-2017-14864 | MEDIUM | 5.5 | 1.1% | Sep 29, 2017 | An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability ca... |
| CVE-2017-14862 | MEDIUM | 5.5 | 1.1% | Sep 29, 2017 | An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerabi... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now