2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2017-10293MEDIUM6.1Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Javadoc). Supported versions that are affected a...
CVE-2017-10286MEDIUM4.4Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are ...
CVE-2017-10281MEDIUM5.3Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Suppo...
CVE-2017-10274MEDIUM6.8Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Smart Card IO). Supported versions that are affe...
CVE-2017-10268MEDIUM4.1Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that...
CVE-2017-13083MEDIUM5.3Akeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over H...
CVE-2017-15289MEDIUM6The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial...
CVE-2017-10621MEDIUM5.3A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unauthenticated attacker...
CVE-2017-10618MEDIUM5.9When the 'bgp-error-tolerance' feature â€" designed to help mitigate remote session resets from malformed path...
CVE-2017-10617MEDIUM5The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an atta...
CVE-2017-10616MEDIUM5.3The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded credentials. Affected relea...
CVE-2017-10614MEDIUM5.3A vulnerability in telnetd service on Junos OS allows a remote attacker to cause a limited memory and/or CPU consumption...
CVE-2017-10613MEDIUM5.5A vulnerability in a specific loopback filter action command, processed in a specific logical order of operation, in a r...
CVE-2017-10611MEDIUM6.5If extended statistics are enabled via 'set chassis extended-statistics', when executing any operation that fetches inte...
CVE-2017-10606MEDIUM4.4Version 4.40 of the TPM (Trusted Platform Module) firmware on Juniper Networks SRX300 Series has a weakness in generatin...
CVE-2017-7352MEDIUM5.4Stored Cross-site scripting (XSS) vulnerability in Pure Storage Purity 4.7.5 allows remote authenticated users to inject...
CVE-2017-15046MEDIUM5.5LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend...
CVE-2017-15018MEDIUM5.5LAME 3.99.5, 3.99.4, 3.99.3, 3.99.2, 3.99.1, 3.99, 3.98.4, 3.98.2 and 3.98 have a heap-based buffer over-read when handl...
CVE-2017-1000101MEDIUM6.5curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers...
CVE-2017-1000100MEDIUM6.5When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 by...
CVE-2017-14955MEDIUM5.9Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, whi...
CVE-2017-14928MEDIUM5.5In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Configuration::Configuration in Annot.cc via a c...
CVE-2017-14926MEDIUM5.5In Poppler 0.59.0, a NULL Pointer Dereference exists in AnnotRichMedia::Content::Content in Annot.cc via a crafted PDF d...
CVE-2017-14864MEDIUM5.5An Invalid memory address dereference was discovered in Exiv2::getULong in types.cpp in Exiv2 0.26. The vulnerability ca...
CVE-2017-14862MEDIUM5.5An Invalid memory address dereference was discovered in Exiv2::DataValue::read in value.cpp in Exiv2 0.26. The vulnerabi...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now