2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-9607 | HIGH | 7 | 0.8% | Sep 20, 2017 | The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure... |
| CVE-2017-14581 | HIGH | 7.5 | 1.7% | Sep 19, 2017 | The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of servi... |
| CVE-2017-14141 | HIGH | 7.2 | 3.1% | Sep 19, 2017 | The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to ... |
| CVE-2017-10931 | HIGH | 7.5 | 1.3% | Sep 19, 2017 | The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resultin... |
| CVE-2017-12615 | HIGH | 8.1 | 99.6% | Sep 19, 2017 | When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati... |
| CVE-2017-9798 | HIGH | 7.5 | 95.0% | Sep 18, 2017 | Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user... |
| CVE-2017-14530 | HIGH | 8 | 0.7% | Sep 18, 2017 | WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=... |
| CVE-2017-9805 | HIGH | 8.1 | 99.5% | Sep 15, 2017 | The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a... |
| CVE-2017-14497 | HIGH | 7.8 | 0.6% | Sep 15, 2017 | The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might ... |
| CVE-2017-4924 | HIGH | 8.8 | 0.6% | Sep 15, 2017 | VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8... |
| CVE-2017-2809 | HIGH | 7.5 | 3.0% | Sep 14, 2017 | An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted... |
| CVE-2017-1002151 | HIGH | 7.5 | 1.1% | Sep 14, 2017 | Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization |
| CVE-2017-13779 | HIGH | 7.8 | 1.1% | Sep 14, 2017 | GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-serve... |
| CVE-2017-2816 | HIGH | 8.8 | 2.4% | Sep 13, 2017 | An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially craft... |
| CVE-2017-14430 | HIGH | 7.5 | 1.4% | Sep 13, 2017 | D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic... |
| CVE-2017-14428 | HIGH | 7.8 | 0.3% | Sep 13, 2017 | D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic... |
| CVE-2017-14427 | HIGH | 7.8 | 0.3% | Sep 13, 2017 | D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic... |
| CVE-2017-14426 | HIGH | 7.8 | 0.3% | Sep 13, 2017 | D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic... |
| CVE-2017-14425 | HIGH | 7.8 | 0.3% | Sep 13, 2017 | D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic... |
| CVE-2017-14424 | HIGH | 7.8 | 0.3% | Sep 13, 2017 | D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic... |
| CVE-2017-14423 | HIGH | 7.5 | 1.0% | Sep 13, 2017 | htdocs/parentalcontrols/bind.php on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices does no... |
| CVE-2017-14422 | HIGH | 7.5 | 1.3% | Sep 13, 2017 | D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic... |
| CVE-2017-14418 | HIGH | 8.1 | 0.8% | Sep 13, 2017 | The D-Link NPAPI extension, as used in conjunction with D-Link DIR-850L REV. B (with firmware through FW208WWb02) device... |
| CVE-2017-14398 | HIGH | 7.8 | 0.3% | Sep 13, 2017 | rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and conseque... |
| CVE-2017-8759 | HIGH | 7.8 | 88.7% | Sep 13, 2017 | Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now