2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-18373 | — | — | 5.4% | May 2, 2019 | The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has three user accounts with defaul... |
| CVE-2017-18372 | — | — | 21.9% | May 2, 2019 | The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerabili... |
| CVE-2017-18371 | — | — | 22.5% | May 2, 2019 | The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passw... |
| CVE-2017-18370 | — | — | 22.9% | May 2, 2019 | The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in t... |
| CVE-2017-18369 | — | — | 67.6% | May 2, 2019 | The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote ... |
| CVE-2017-16558 | — | — | 1.2% | Apr 25, 2019 | Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the list... |
| CVE-2017-18367 | — | — | 2.5% | Apr 24, 2019 | libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A pro... |
| CVE-2017-15716 | — | — | — | Apr 23, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2017-12619 | — | — | 4.9% | Apr 23, 2019 | Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user sessi... |
| CVE-2017-7777 | — | — | 1.2% | Apr 15, 2019 | Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph funct... |
| CVE-2017-7776 | — | — | 2.8% | Apr 15, 2019 | Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. |
| CVE-2017-7774 | — | — | 1.4% | Apr 15, 2019 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. |
| CVE-2017-7773 | — | — | 1.4% | Apr 15, 2019 | Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. |
| CVE-2017-7771 | — | — | 1.2% | Apr 15, 2019 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. |
| CVE-2017-18366 | — | — | 0.7% | Apr 15, 2019 | Subrion CMS 4.1.5 has CSRF in blog/delete/. |
| CVE-2017-7775 | — | — | — | Apr 15, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2017-7772 | — | — | 1.4% | Apr 12, 2019 | Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. |
| CVE-2017-14199 | — | — | 1.7% | Apr 12, 2019 | A buffer overflow has been found in the Zephyr Project's getaddrinfo() implementation in 1.9.0 and 1.10.0. |
| CVE-2017-17023 | — | — | 0.6% | Apr 9, 2019 | The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected cli... |
| CVE-2017-7912 | — | — | 4.8% | Apr 8, 2019 | Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and ... |
| CVE-2017-7151 | — | — | 1.0% | Apr 3, 2019 | A race condition was addressed with additional validation. This issue affected versions prior to iOS 11.2, macOS High Si... |
| CVE-2017-13911 | — | — | 0.9% | Apr 3, 2019 | A configuration issue was addressed with additional restrictions. This issue affected versions prior to macOS X El Capit... |
| CVE-2017-6049 | — | — | 1.3% | Apr 2, 2019 | Detcon Sitewatch Gateway, all versions without cellular, an attacker can edit settings on the device using a specially c... |
| CVE-2017-6047 | — | — | 1.8% | Apr 2, 2019 | Detcon Sitewatch Gateway, all versions without cellular, Passwords are presented in plaintext in a file that is accessib... |
| CVE-2017-18111 | — | — | 1.7% | Mar 29, 2019 | The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now