2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7440 | MEDIUM | 6.5 | 0.9% | May 2, 2017 | Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2,... |
| CVE-2017-8339 | MEDIUM | 5.5 | 0.4% | Apr 30, 2017 | PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoCon... |
| CVE-2017-2134 | MEDIUM | 6.1 | 1.2% | Apr 28, 2017 | Cross-site scripting vulnerability in ASSETBASE 8.0 and earlier allows remote attackers to inject arbitrary web script o... |
| CVE-2017-3008 | MEDIUM | 6.1 | 3.1% | Apr 27, 2017 | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav... |
| CVE-2017-5046 | MEDIUM | 4.3 | 1.3% | Apr 24, 2017 | V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android had insufficient pol... |
| CVE-2017-5045 | MEDIUM | 6.1 | 1.2% | Apr 24, 2017 | XSS Auditor in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed det... |
| CVE-2017-5044 | MEDIUM | 6.3 | 2.4% | Apr 24, 2017 | Heap buffer overflow in filter processing in Skia in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and... |
| CVE-2017-5042 | MEDIUM | 5.7 | 0.4% | Apr 24, 2017 | Cast in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android sent cookies to si... |
| CVE-2017-5040 | MEDIUM | 4.3 | 22.1% | Apr 24, 2017 | V8 in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android was missing a neuter... |
| CVE-2017-5038 | MEDIUM | 6.3 | 1.1% | Apr 24, 2017 | Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, wh... |
| CVE-2017-5033 | MEDIUM | 4.3 | 1.5% | Apr 24, 2017 | Blink in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android failed to correct... |
| CVE-2017-3600 | MEDIUM | 6.6 | 2.6% | Apr 24, 2017 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that ar... |
| CVE-2017-3577 | MEDIUM | 6.5 | 1.7% | Apr 24, 2017 | Vulnerability in the PeopleSoft Enterprise CS Campus Community component of Oracle PeopleSoft Products (subcomponent: Fr... |
| CVE-2017-3571 | MEDIUM | 6.5 | 1.9% | Apr 24, 2017 | Vulnerability in the PeopleSoft Enterprise SCM eBill Payment component of Oracle PeopleSoft Products (subcomponent: Secu... |
| CVE-2017-3464 | MEDIUM | 4.3 | 2.1% | Apr 24, 2017 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are aff... |
| CVE-2017-3456 | MEDIUM | 4.9 | 3.0% | Apr 24, 2017 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are aff... |
| CVE-2017-3453 | MEDIUM | 6.5 | 3.1% | Apr 24, 2017 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that a... |
| CVE-2017-5160 | MEDIUM | 5.3 | 0.5% | Apr 20, 2017 | An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version... |
| CVE-2017-2806 | MEDIUM | 4.3 | 0.9% | Apr 20, 2017 | An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functiona... |
| CVE-2017-7718 | MEDIUM | 5.5 | 0.5% | Apr 20, 2017 | hw/display/cirrus_vga_rop.h in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of ser... |
| CVE-2017-7938 | MEDIUM | 6.6 | 5.0% | Apr 20, 2017 | Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau... |
| CVE-2017-7188 | MEDIUM | 5.4 | 1.4% | Apr 14, 2017 | Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in... |
| CVE-2017-7725 | MEDIUM | 6.1 | 2.8% | Apr 13, 2017 | concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "ca... |
| CVE-2017-7697 | MEDIUM | 5.5 | 0.9% | Apr 11, 2017 | In libsamplerate before 0.1.9, a buffer over-read occurs in the calc_output_single function in src_sinc.c via a crafted ... |
| CVE-2017-7377 | MEDIUM | 6 | 0.4% | Apr 10, 2017 | The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS pri... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now