2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-17456Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-14245. Reason: This candidate is a duplicate of ...
CVE-2017-17430Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands vi...
CVE-2017-17384ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.
CVE-2017-17381MEDIUM6.5The Virtio Vring implementation in QEMU allows local OS guest users to cause a denial of service (divide-by-zero error a...
CVE-2017-17055Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site...
CVE-2017-16884Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web scrip...
CVE-2017-15121A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a h...
CVE-2017-17451The WP Mailster plugin before 1.5.5 for WordPress has XSS in the unsubscribe handler via the mes parameter to view/subsc...
CVE-2017-17450net/netfilter/xt_osf.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for add_callback...
CVE-2017-17449The __netlink_deliver_tap_skb function in net/netlink/af_netlink.c in the Linux kernel through 4.14.4, when CONFIG_NLMON...
CVE-2017-17448net/netfilter/nfnetlink_cthelper.c in the Linux kernel through 4.14.4 does not require the CAP_NET_ADMIN capability for ...
CVE-2017-17436An issue was discovered in the software on Vaultek Gun Safe VT20i products. There is no encryption of the session betwee...
CVE-2017-17435An issue was discovered in the software on Vaultek Gun Safe VT20i products, aka BlueSteal. An attacker can remotely unlo...
CVE-2017-17446The Mem_File_Reader::read_avail function in Data_Reader.cpp in the Game_Music_Emu library (aka game-music-emu) 0.6.1 doe...
CVE-2017-17068A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerabi...
CVE-2017-6276NVIDIA mediaserver contains a vulnerability where it is possible a use after free malfunction can occur due to an incorr...
CVE-2017-6263NVIDIA driver contains a vulnerability where it is possible a use after free malfunction can occur due to improper usage...
CVE-2017-6262NVIDIA driver contains a vulnerability where it is possible a use after free malfunction can occur due to a race conditi...
CVE-2017-17440GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application cras...
CVE-2017-17439In Heimdal through 7.4, remote unauthenticated attackers are able to crash the KDC by sending a crafted UDP packet conta...
CVE-2017-13175An information disclosure vulnerability in the NVIDIA libwilhelm. Product: Android. Versions: Android kernel. Android ID...
CVE-2017-13174An elevation of privilege vulnerability in the kernel edl. Product: Android. Versions: Android kernel. Android ID A-6310...
CVE-2017-13173An elevation of privilege vulnerability in the MediaTek system server. Product: Android. Versions: Android kernel. Andro...
CVE-2017-13172An elevation of privilege vulnerability in the MediaTek bluetooth driver. Product: Android. Versions: Android kernel. An...
CVE-2017-13171An elevation of privilege vulnerability in the MediaTek performance service. Product: Android. Versions: Android kernel....

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now