2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2017-7529HIGH7.5Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range fi...
CVE-2017-11103HIGH8.1Heimdal before 7.4 allows remote attackers to impersonate services with Orpheus' Lyre attacks because it obtains service...
CVE-2017-11173HIGH8.8Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS request...
CVE-2017-2863HIGH7.8An out-of-bounds write vulnerability exists in the PDF parsing functionality of Infix 7.1.5. A specially crafted PDF fil...
CVE-2017-2820HIGH8.8An exploitable integer overflow vulnerability exists in the JPEG 2000 image parsing functionality of freedesktop.org Pop...
CVE-2017-2818HIGH7.5An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically...
CVE-2017-2814HIGH7.5An exploitable heap overflow vulnerability exists in the image rendering functionality of Poppler 0.53.0. A specifically...
CVE-2017-9844HIGH7.5SAP NetWeaver 7400.12.21.30308 allows remote attackers to cause a denial of service and possibly execute arbitrary code ...
CVE-2017-11176HIGH7.8The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr...
CVE-2017-8570HIGH7.8Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic...
CVE-2017-8561HIGH7Windows kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, a...
CVE-2017-7730HIGH7.5iSmartAlarm cube devices allow Denial of Service. Sending a SYN flood on port 12345 will freeze the "cube" and it will s...
CVE-2017-7729HIGH7.5On iSmartAlarm cube devices, there is Incorrect Access Control because a "new key" is transmitted in cleartext.
CVE-2017-7726HIGH7.5iSmartAlarm cube devices have an SSL Certificate Validation Vulnerability.
CVE-2017-11113HIGH7.5In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lea...
CVE-2017-11112HIGH7.5In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It co...
CVE-2017-9631HIGH7.5A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.230...
CVE-2017-9627HIGH8.6An Uncontrolled Resource Consumption issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 20...
CVE-2017-1000381HIGH7.5The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read me...
CVE-2017-2244HIGH8.8Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hij...
CVE-2017-2226HIGH7.8Untrusted search path vulnerability in Setup file of advance preparation for e-Tax software (WEB version) (1.17.1) and e...
CVE-2017-7404HIGH8.8On the D-Link DIR-615 before v20.12PTb04, if a victim logged in to the Router's Web Interface visits a malicious site fr...
CVE-2017-9524HIGH7.5The qemu-nbd server in QEMU (aka Quick Emulator), when built with the Network Block Device (NBD) Server support, allows ...
CVE-2017-8803HIGH7.8Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted...
CVE-2017-10810HIGH7.5Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel thro...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now