2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-15650musl libc before 1.1.17 has a buffer overflow via crafted DNS replies because dns_parse_callback in network/lookup_name....
CVE-2017-14019An Unquoted Search Path or Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An unquoted searc...
CVE-2017-14017An Uncontrolled Search Path Element issue was discovered in Progea Movicon Version 11.5.1181 and prior. An uncontrolled ...
CVE-2017-15649net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls ...
CVE-2017-15648In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter.
CVE-2017-15647On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a cra...
CVE-2017-15646Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Down...
CVE-2017-15645CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker...
CVE-2017-15644SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/h...
CVE-2017-15643An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKA...
CVE-2017-10933All versions prior to V2.06.00.00 of ZTE ZXDT22 SF01, an monitoring system of ZTE energy product, are impacted by direct...
CVE-2017-5636In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, the proxy chain serialization/deserialization...
CVE-2017-5635In Apache NiFi before 0.7.2 and 1.x before 1.1.2 in a cluster environment, if an anonymous user request is replicated to...
CVE-2017-15642In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supp...
CVE-2017-15639tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the ...
CVE-2017-10955HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection ...
CVE-2017-3588Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: HA for MySQL). Suppor...
CVE-2017-3446Vulnerability in the Oracle Trade Management component of Oracle E-Business Suite (subcomponent: User Interface). Suppor...
CVE-2017-3445Vulnerability in the Oracle Trade Management component of Oracle E-Business Suite (subcomponent: User Interface). Suppor...
CVE-2017-3444Vulnerability in the Oracle Trade Management component of Oracle E-Business Suite (subcomponent: User Interface). Suppor...
CVE-2017-10428Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version...
CVE-2017-10427Vulnerability in the Oracle Retail Xstore Point of Service component of Oracle Retail Applications (subcomponent: Point ...
CVE-2017-10426Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: Staffing Front Of...
CVE-2017-10425Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Service Hos...
CVE-2017-10424Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: Web). Supported versi...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now