2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-16674Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-...
CVE-2017-16673Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonat...
CVE-2017-16672An issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1 and Certified ...
CVE-2017-16671A Buffer Overflow issue was discovered in Asterisk Open Source 13 before 13.18.1, 14 before 14.7.1, and 15 before 15.1.1...
CVE-2017-16669coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow a...
CVE-2017-11512The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the path...
CVE-2017-11511The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the path...
CVE-2017-15865bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, all...
CVE-2017-15087It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster...
CVE-2017-15086It was discovered that the fix for CVE-2017-12151 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster...
CVE-2017-15085It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster...
CVE-2017-16667backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify...
CVE-2017-16665RemObjects Remoting SDK 9 1.0.0.0 for Delphi is vulnerable to a reflected Cross Site Scripting (XSS) attack via the serv...
CVE-2017-9096The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote a...
CVE-2017-14360MEDIUM5.9A potential security vulnerability has been identified in HPE Content Manager Workgroup Service v9.00. The vulnerability...
CVE-2017-12824Special crafted InPage document leads to arbitrary code execution in InPage reader.
CVE-2017-16663In sam2p 0.49.4, there are integer overflows (with resultant heap-based buffer overflows) in input-bmp.ci in the functio...
CVE-2017-16661Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private d...
CVE-2017-16660Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path...
CVE-2017-16659HIGH7.8The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access t...
CVE-2017-16618An exploitable vulnerability exists in the YAML loading functionality of util.py in OwlMixin before 2.0.0a12. A "Load YA...
CVE-2017-16616An exploitable vulnerability exists in the YAML parsing functionality in the YAMLParser method in Interfaces.py in PyAny...
CVE-2017-16615An exploitable vulnerability exists in the YAML parsing functionality in the parse_yaml_query method in parser.py in MLA...
CVE-2017-16650The qmi_wwan_bind function in drivers/net/usb/qmi_wwan.c in the Linux kernel through 4.13.11 allows local users to cause...
CVE-2017-16649The usbnet_generic_cdc_bind function in drivers/net/usb/cdc_ether.c in the Linux kernel through 4.13.11 allows local use...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now