2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17456 | — | — | — | Dec 7, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-14245. Reason: This candidate is a duplicate of ... |
| CVE-2017-17430 | — | — | 1.8% | Dec 7, 2017 | Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands vi... |
| CVE-2017-17384 | — | — | 1.5% | Dec 7, 2017 | ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job. |
| CVE-2017-17381 | MEDIUM | 6.5 | 0.4% | Dec 7, 2017 | The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error a... |
| CVE-2017-17055 | — | — | 8.7% | Dec 7, 2017 | Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site... |
| CVE-2017-16884 | — | — | 4.3% | Dec 7, 2017 | Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web scrip... |
| CVE-2017-15121 | — | — | 0.4% | Dec 7, 2017 | A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a h... |
| CVE-2017-17451 | — | — | 5.1% | Dec 7, 2017 | The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subsc... |
| CVE-2017-17450 | — | — | 0.4% | Dec 7, 2017 | net/netfilter/xt_osf.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for add_callback... |
| CVE-2017-17449 | — | — | 0.4% | Dec 7, 2017 | The __netlink_deliver_tap_skb function in net/netlink/af_netlink.c in the Linux kernel through 4.14.4, when CONFIG_NLMON... |
| CVE-2017-17448 | — | — | 0.4% | Dec 7, 2017 | net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for ... |
| CVE-2017-17436 | — | — | 0.2% | Dec 7, 2017 | An issue was discovered in the software on Vaultek Gun Safe VT20i products. There is no encryption of the session betwee... |
| CVE-2017-17435 | — | — | 0.6% | Dec 7, 2017 | An issue was discovered in the software on Vaultek Gun Safe VT20i products, aka BlueSteal. An attacker can remotely unlo... |
| CVE-2017-17446 | — | — | 1.5% | Dec 6, 2017 | The Mem_File_Reader::read_avail function in Data_Reader.cpp in the Game_Music_Emu library (aka game-music-emu) 0.6.1 doe... |
| CVE-2017-17068 | — | — | 1.4% | Dec 6, 2017 | A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerabi... |
| CVE-2017-6276 | — | — | 0.2% | Dec 6, 2017 | NVIDIA mediaserver contains a vulnerability where it is possible a use after free malfunction can occur due to an incorr... |
| CVE-2017-6263 | — | — | 0.2% | Dec 6, 2017 | NVIDIA driver contains a vulnerability where it is possible a use after free malfunction can occur due to improper usage... |
| CVE-2017-6262 | — | — | 0.2% | Dec 6, 2017 | NVIDIA driver contains a vulnerability where it is possible a use after free malfunction can occur due to a race conditi... |
| CVE-2017-17440 | — | — | 2.4% | Dec 6, 2017 | GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application cras... |
| CVE-2017-17439 | — | — | 3.4% | Dec 6, 2017 | In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet conta... |
| CVE-2017-13175 | — | — | 0.4% | Dec 6, 2017 | An information disclosure vulnerability in the NVIDIA libwilhelm. Product: Android. Versions: Android kernel. Android ID... |
| CVE-2017-13174 | — | — | 0.2% | Dec 6, 2017 | An elevation of privilege vulnerability in the kernel edl. Product: Android. Versions: Android kernel. Android ID A-6310... |
| CVE-2017-13173 | — | — | 0.2% | Dec 6, 2017 | An elevation of privilege vulnerability in the MediaTek system server. Product: Android. Versions: Android kernel. Andro... |
| CVE-2017-13172 | — | — | 0.1% | Dec 6, 2017 | An elevation of privilege vulnerability in the MediaTek bluetooth driver. Product: Android. Versions: Android kernel. An... |
| CVE-2017-13171 | — | — | 0.2% | Dec 6, 2017 | An elevation of privilege vulnerability in the MediaTek performance service. Product: Android. Versions: Android kernel.... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now