2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2017-8936MEDIUM5.9The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 c...
CVE-2017-8935MEDIUM5.9The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, whi...
CVE-2017-8906MEDIUM5.5An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x...
CVE-2017-2681MEDIUM6.5Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a d...
CVE-2017-2680MEDIUM6.5Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a loc...
CVE-2017-8876MEDIUM6.1Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.
CVE-2017-5527MEDIUM4.3TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7...
CVE-2017-0894MEDIUM4.3Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical e...
CVE-2017-0890MEDIUM5.4Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search modu...
CVE-2017-8847MEDIUM5.5The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial...
CVE-2017-8846MEDIUM5.5The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service ...
CVE-2017-8845MEDIUM5.5The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a deni...
CVE-2017-8843MEDIUM5.5The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service...
CVE-2017-8842MEDIUM5.5The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial...
CVE-2017-8831MEDIUM6.4The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local ...
CVE-2017-6024MEDIUM5.9A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V2...
CVE-2017-8060MEDIUM5.9Acceptance of invalid/self-signed TLS certificates in "Panda Mobile Security" 1.1 for iOS allows a man-in-the-middle and...
CVE-2017-5914MEDIUM5.9The DOT IT Banque Zitouna app 2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-m...
CVE-2017-5905MEDIUM5.9The Dollar Bank Mobile app 2.6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-mi...
CVE-2017-5902MEDIUM5.9The PayQuicker app 1.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att...
CVE-2017-3212MEDIUM5.9The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from S...
CVE-2017-3732MEDIUM5.9There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 be...
CVE-2017-8459MEDIUM5.3Brave 0.12.4 has a Status Bar Obfuscation issue in which a redirection target is shown in a possibly unexpected way. NOT...
CVE-2017-8112MEDIUM6.5hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (i...
CVE-2017-8086MEDIUM6.5Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS pri...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now