2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-16648 | — | — | 0.4% | Nov 7, 2017 | The dvb_frontend_free function in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel through 4.13.11 allows local... |
| CVE-2017-16647 | — | — | 0.4% | Nov 7, 2017 | drivers/net/usb/asix_devices.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (NULL... |
| CVE-2017-16646 | — | — | 0.4% | Nov 7, 2017 | drivers/media/usb/dvb-usb/dib0700_devices.c in the Linux kernel through 4.13.11 allows local users to cause a denial of ... |
| CVE-2017-16645 | — | — | 0.4% | Nov 7, 2017 | The ims_pcu_get_cdc_union_desc function in drivers/input/misc/ims-pcu.c in the Linux kernel through 4.13.11 allows local... |
| CVE-2017-16644 | — | — | 0.4% | Nov 7, 2017 | The hdpvr_probe function in drivers/media/usb/hdpvr/hdpvr-core.c in the Linux kernel through 4.13.11 allows local users ... |
| CVE-2017-16643 | — | — | 0.5% | Nov 7, 2017 | The parse_hid_report_descriptor function in drivers/input/tablet/gtco.c in the Linux kernel before 4.13.11 allows local ... |
| CVE-2017-16561 | — | — | 1.4% | Nov 7, 2017 | /view/friend_profile.php in Ingenious School Management System 2.3.0 is vulnerable to Boolean-based and Time-based SQL i... |
| CVE-2017-16642 | — | — | 26.4% | Nov 7, 2017 | In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian hand... |
| CVE-2017-16641 | — | — | 3.2% | Nov 7, 2017 | lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrd... |
| CVE-2017-2922 | CRITICAL | 9.8 | 2.6% | Nov 7, 2017 | An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. ... |
| CVE-2017-2921 | CRITICAL | 9.8 | 2.4% | Nov 7, 2017 | An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. ... |
| CVE-2017-2917 | HIGH | 8.8 | 3.2% | Nov 7, 2017 | An exploitable vulnerability exists in the notifications functionality of Circle with Disney running firmware 2.0.1. Spe... |
| CVE-2017-2916 | HIGH | 8.8 | 2.3% | Nov 7, 2017 | An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.... |
| CVE-2017-2915 | HIGH | 8 | 1.4% | Nov 7, 2017 | An exploitable vulnerability exists in the WiFi configuration functionality of Circle with Disney running firmware 2.0.1... |
| CVE-2017-2914 | HIGH | 8.1 | 1.6% | Nov 7, 2017 | An exploitable authentication bypass vulnerability exists in the API daemon of Circle with Disney running firmware 2.0.1... |
| CVE-2017-2913 | MEDIUM | 5.9 | 0.7% | Nov 7, 2017 | An exploitable vulnerability exists in the filtering functionality of Circle with Disney. SSL certificates for specific ... |
| CVE-2017-2912 | MEDIUM | 5.9 | 0.7% | Nov 7, 2017 | An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SS... |
| CVE-2017-2911 | MEDIUM | 5.9 | 0.7% | Nov 7, 2017 | An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SS... |
| CVE-2017-2909 | HIGH | 7.5 | 1.4% | Nov 7, 2017 | An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially c... |
| CVE-2017-2898 | HIGH | 7.5 | 1.6% | Nov 7, 2017 | An exploitable vulnerability exists in the signature verification of the firmware update functionality of Circle with Di... |
| CVE-2017-2895 | HIGH | 8.2 | 1.3% | Nov 7, 2017 | An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6... |
| CVE-2017-2894 | CRITICAL | 9.8 | 31.0% | Nov 7, 2017 | An exploitable stack buffer overflow vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6... |
| CVE-2017-2893 | HIGH | 7.5 | 26.6% | Nov 7, 2017 | An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoos... |
| CVE-2017-2892 | CRITICAL | 9.8 | 2.4% | Nov 7, 2017 | An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6... |
| CVE-2017-2891 | CRITICAL | 9.8 | 2.8% | Nov 7, 2017 | An exploitable use-after-free vulnerability exists in the HTTP server implementation of Cesanta Mongoose 6.8. An ordinar... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now