2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2017-9607HIGH7The BL1 FWU SMC handling code in ARM Trusted Firmware before 1.4 might allow attackers to write arbitrary data to secure...
CVE-2017-14581HIGH7.5The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of servi...
CVE-2017-14141HIGH7.2The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to ...
CVE-2017-10931HIGH7.5The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resultin...
CVE-2017-12615HIGH8.1When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati...
CVE-2017-9798HIGH7.5Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user...
CVE-2017-14530HIGH8WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=...
CVE-2017-9805HIGH8.1The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a...
CVE-2017-14497HIGH7.8The tpacket_rcv function in net/packet/af_packet.c in the Linux kernel before 4.13 mishandles vnet headers, which might ...
CVE-2017-4924HIGH8.8VMware ESXi (ESXi 6.5 without patch ESXi650-201707101-SG), Workstation (12.x before 12.5.7) and Fusion (8.x before 8.5.8...
CVE-2017-2809HIGH7.5An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted...
CVE-2017-1002151HIGH7.5Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization
CVE-2017-13779HIGH7.8GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-serve...
CVE-2017-2816HIGH8.8An exploitable buffer overflow vulnerability exists in the tag parsing functionality of LibOFX 0.9.11. A specially craft...
CVE-2017-14430HIGH7.5D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic...
CVE-2017-14428HIGH7.8D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic...
CVE-2017-14427HIGH7.8D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic...
CVE-2017-14426HIGH7.8D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic...
CVE-2017-14425HIGH7.8D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic...
CVE-2017-14424HIGH7.8D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic...
CVE-2017-14423HIGH7.5htdocs/parentalcontrols/bind.php on D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) devices does no...
CVE-2017-14422HIGH7.5D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devic...
CVE-2017-14418HIGH8.1The D-Link NPAPI extension, as used in conjunction with D-Link DIR-850L REV. B (with firmware through FW208WWb02) device...
CVE-2017-14398HIGH7.8rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and conseque...
CVE-2017-8759HIGH7.8Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now