2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8936 | MEDIUM | 5.9 | 0.6% | May 15, 2017 | The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 c... |
| CVE-2017-8935 | MEDIUM | 5.9 | 0.6% | May 15, 2017 | The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, whi... |
| CVE-2017-8906 | MEDIUM | 5.5 | 0.8% | May 11, 2017 | An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x... |
| CVE-2017-2681 | MEDIUM | 6.5 | 0.9% | May 11, 2017 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a d... |
| CVE-2017-2680 | MEDIUM | 6.5 | 1.1% | May 11, 2017 | Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a loc... |
| CVE-2017-8876 | MEDIUM | 6.1 | 0.8% | May 10, 2017 | Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php. |
| CVE-2017-5527 | MEDIUM | 4.3 | 0.9% | May 9, 2017 | TIBCO Spotfire Server 7.0.X before 7.0.2, 7.5.x before 7.5.1, 7.6.x before 7.6.1, 7.7.x before 7.7.1, and 7.8.x before 7... |
| CVE-2017-0894 | MEDIUM | 4.3 | 1.2% | May 8, 2017 | Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical e... |
| CVE-2017-0890 | MEDIUM | 5.4 | 0.7% | May 8, 2017 | Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search modu... |
| CVE-2017-8847 | MEDIUM | 5.5 | 1.4% | May 8, 2017 | The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial... |
| CVE-2017-8846 | MEDIUM | 5.5 | 1.6% | May 8, 2017 | The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service ... |
| CVE-2017-8845 | MEDIUM | 5.5 | 1.4% | May 8, 2017 | The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a deni... |
| CVE-2017-8843 | MEDIUM | 5.5 | 1.4% | May 8, 2017 | The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service... |
| CVE-2017-8842 | MEDIUM | 5.5 | 1.6% | May 8, 2017 | The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial... |
| CVE-2017-8831 | MEDIUM | 6.4 | 0.4% | May 8, 2017 | The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local ... |
| CVE-2017-6024 | MEDIUM | 5.9 | 2.6% | May 6, 2017 | A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V2... |
| CVE-2017-8060 | MEDIUM | 5.9 | 0.7% | May 5, 2017 | Acceptance of invalid/self-signed TLS certificates in "Panda Mobile Security" 1.1 for iOS allows a man-in-the-middle and... |
| CVE-2017-5914 | MEDIUM | 5.9 | 0.6% | May 5, 2017 | The DOT IT Banque Zitouna app 2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-m... |
| CVE-2017-5905 | MEDIUM | 5.9 | 0.5% | May 5, 2017 | The Dollar Bank Mobile app 2.6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-mi... |
| CVE-2017-5902 | MEDIUM | 5.9 | 0.5% | May 5, 2017 | The PayQuicker app 1.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att... |
| CVE-2017-3212 | MEDIUM | 5.9 | 0.8% | May 5, 2017 | The Space Coast Credit Union Mobile app 2.2 for iOS and 2.1.0.1104 for Android does not verify X.509 certificates from S... |
| CVE-2017-3732 | MEDIUM | 5.9 | 15.9% | May 4, 2017 | There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 be... |
| CVE-2017-8459 | MEDIUM | 5.3 | 0.7% | May 3, 2017 | Brave 0.12.4 has a Status Bar Obfuscation issue in which a redirection target is shown in a possibly unexpected way. NOT... |
| CVE-2017-8112 | MEDIUM | 6.5 | 0.4% | May 2, 2017 | hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (i... |
| CVE-2017-8086 | MEDIUM | 6.5 | 0.4% | May 2, 2017 | Memory leak in the v9fs_list_xattr function in hw/9pfs/9p-xattr.c in QEMU (aka Quick Emulator) allows local guest OS pri... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now