2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7529 | HIGH | 7.5 | 62.6% | Jul 13, 2017 | Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range fi... |
| CVE-2017-11103 | HIGH | 8.1 | 5.1% | Jul 13, 2017 | Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service... |
| CVE-2017-11173 | HIGH | 8.8 | 2.3% | Jul 13, 2017 | Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS request... |
| CVE-2017-2863 | HIGH | 7.8 | 1.2% | Jul 12, 2017 | An out-of-bounds write vulnerability exists in the PDF parsing functionality of Infix 7.1.5. A specially crafted PDF fil... |
| CVE-2017-2820 | HIGH | 8.8 | 4.4% | Jul 12, 2017 | An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Pop... |
| CVE-2017-2818 | HIGH | 7.5 | 2.0% | Jul 12, 2017 | An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically... |
| CVE-2017-2814 | HIGH | 7.5 | 2.7% | Jul 12, 2017 | An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically... |
| CVE-2017-9844 | HIGH | 7.5 | 5.5% | Jul 12, 2017 | SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code ... |
| CVE-2017-11176 | HIGH | 7.8 | 3.6% | Jul 11, 2017 | The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr... |
| CVE-2017-8570 | HIGH | 7.8 | 89.9% | Jul 11, 2017 | Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic... |
| CVE-2017-8561 | HIGH | 7 | 0.8% | Jul 11, 2017 | Windows kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, a... |
| CVE-2017-7730 | HIGH | 7.5 | 1.3% | Jul 11, 2017 | iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will s... |
| CVE-2017-7729 | HIGH | 7.5 | 0.7% | Jul 11, 2017 | On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext. |
| CVE-2017-7726 | HIGH | 7.5 | 0.7% | Jul 11, 2017 | iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability. |
| CVE-2017-11113 | HIGH | 7.5 | 2.4% | Jul 8, 2017 | In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lea... |
| CVE-2017-11112 | HIGH | 7.5 | 2.2% | Jul 8, 2017 | In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It co... |
| CVE-2017-9631 | HIGH | 7.5 | 3.2% | Jul 7, 2017 | A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.230... |
| CVE-2017-9627 | HIGH | 8.6 | 4.1% | Jul 7, 2017 | An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 20... |
| CVE-2017-1000381 | HIGH | 7.5 | 3.3% | Jul 7, 2017 | The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read me... |
| CVE-2017-2244 | HIGH | 8.8 | 0.7% | Jul 7, 2017 | Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hij... |
| CVE-2017-2226 | HIGH | 7.8 | 1.1% | Jul 7, 2017 | Untrusted search path vulnerability in Setup file of advance preparation for e-Tax software (WEB version) (1.17.1) and e... |
| CVE-2017-7404 | HIGH | 8.8 | 0.6% | Jul 7, 2017 | On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site fr... |
| CVE-2017-9524 | HIGH | 7.5 | 4.1% | Jul 6, 2017 | The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows ... |
| CVE-2017-8803 | HIGH | 7.8 | 1.6% | Jul 5, 2017 | Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted... |
| CVE-2017-10810 | HIGH | 7.5 | 3.8% | Jul 4, 2017 | Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel thro... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now