2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-15102 | — | — | 0.4% | Nov 15, 2017 | The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are... |
| CVE-2017-15923 | — | — | 2.7% | Nov 15, 2017 | Konversation 1.4.x, 1.5.x, 1.6.x, and 1.7.x before 1.7.3 allow remote attackers to cause a denial of service (crash) via... |
| CVE-2017-15806 | — | — | 10.7% | Nov 15, 2017 | The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the s... |
| CVE-2017-15288 | HIGH | 7.8 | 0.4% | Nov 15, 2017 | The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for... |
| CVE-2017-15272 | — | — | 0.6% | Nov 15, 2017 | The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database ... |
| CVE-2017-15271 | — | — | 8.7% | Nov 15, 2017 | A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be... |
| CVE-2017-15270 | — | — | 7.0% | Nov 15, 2017 | The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) f... |
| CVE-2017-15269 | — | — | 1.5% | Nov 15, 2017 | The PSFTPd 10.0.4 Build 729 server does not prevent FTP bounce scans by default. These can be performed using "nmap -b" ... |
| CVE-2017-14961 | — | — | 1.5% | Nov 15, 2017 | In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating ... |
| CVE-2017-12634 | — | — | 7.2% | Nov 15, 2017 | The camel-castor component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-se... |
| CVE-2017-12633 | — | — | 7.1% | Nov 15, 2017 | The camel-hessian component in Apache Camel 2.x before 2.19.4 and 2.20.x before 2.20.1 is vulnerable to Java object de-s... |
| CVE-2017-16833 | MEDIUM | 6.1 | 0.8% | Nov 15, 2017 | Stored cross-site scripting (XSS) vulnerability in Gemirro before 0.16.0 allows attackers to inject arbitrary web script... |
| CVE-2017-8815 | — | — | 1.6% | Nov 15, 2017 | The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injec... |
| CVE-2017-8814 | — | — | 1.6% | Nov 15, 2017 | The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to re... |
| CVE-2017-8812 | — | — | 1.6% | Nov 15, 2017 | MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows remote attackers to inject > (greater tha... |
| CVE-2017-8811 | — | — | 1.0% | Nov 15, 2017 | The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x befor... |
| CVE-2017-8810 | — | — | 2.1% | Nov 15, 2017 | MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2, when a private wiki is configured, provides dif... |
| CVE-2017-8809 | — | — | 7.7% | Nov 15, 2017 | api.php in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has a Reflected File Download vulnera... |
| CVE-2017-8808 | — | — | 1.0% | Nov 15, 2017 | MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 has XSS when the $wgShowExceptionDetails setting... |
| CVE-2017-7851 | — | — | 2.5% | Nov 15, 2017 | D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the devi... |
| CVE-2017-16832 | — | — | 1.8% | Nov 15, 2017 | The pe_bfd_read_buildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed i... |
| CVE-2017-16831 | — | — | 1.8% | Nov 15, 2017 | coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not vali... |
| CVE-2017-16830 | — | — | 2.2% | Nov 15, 2017 | The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does not have integer-overflow protection on 32... |
| CVE-2017-16829 | — | — | 1.8% | Nov 15, 2017 | The _bfd_elf_parse_gnu_properties function in elf-properties.c in the Binary File Descriptor (BFD) library (aka libbfd),... |
| CVE-2017-16828 | — | — | 1.8% | Nov 15, 2017 | The display_debug_frames function in dwarf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now