2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-13784An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud...
CVE-2017-13783An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud...
CVE-2017-13782An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" com...
CVE-2017-16799In CMS Made Simple 2.2.3.1, in modules/New/action.addcategory.php, stored XSS is possible via the m1_name parameter to a...
CVE-2017-16798MEDIUM5.4In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file ex...
CVE-2017-16797In SWFTools 0.9.2, the png_load function in lib/png.c does not properly validate an alloclen_64 multiplication of width ...
CVE-2017-16796In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows re...
CVE-2017-16794The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-p...
CVE-2017-16793The wav_convert2mono function in lib/wav.c in SWFTools 0.9.2 does not properly validate WAV data, which allows remote at...
CVE-2017-16520Inedo BuildMaster before 5.8.2 does not properly restrict creation of RequireManageAllPrivileges event listeners.
CVE-2017-16785Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php.
CVE-2017-16784In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.
CVE-2017-16783CRITICAL9.8In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
CVE-2017-16782In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markd...
CVE-2017-16781The installer in MyBB before 1.8.13 has XSS.
CVE-2017-16780The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration fi...
CVE-2017-16765MEDIUM6.1XSS exists on D-Link DWR-933 1.00(WW)B17 devices via cgi-bin/gui.cgi.
CVE-2017-16764CRITICAL9.8An exploitable vulnerability exists in the YAML parsing functionality in the read_yaml_file method in io_utils.py in dja...
CVE-2017-16763An exploitable vulnerability exists in the YAML parsing functionality in config.py in Confire 0.2.0. Due to the user-spe...
CVE-2017-16762Sanic before 0.5.1 allows reading arbitrary files with directory traversal, as demonstrated by the /static/..%2f substri...
CVE-2017-16761An Open Redirect vulnerability in Inedo BuildMaster before 5.8.2 allows remote attackers to redirect users to arbitrary ...
CVE-2017-16760Inedo BuildMaster before 5.8.2 has XSS.
CVE-2017-16521In Inedo BuildMaster before 5.8.2, XslTransform was used where XslCompiledTransform should have been used.
CVE-2017-9758Savitech driver packages for Windows silently install a self-signed certificate into the Trusted Root Certification Auth...
CVE-2017-5201NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allow remote authenticated users to obtain sensitive cluste...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now