2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-13082 | — | — | 4.6% | Oct 17, 2017 | Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PT... |
| CVE-2017-13081 | — | — | 2.0% | Oct 17, 2017 | Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal K... |
| CVE-2017-13080 | — | — | 2.3% | Oct 17, 2017 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handsha... |
| CVE-2017-13079 | — | — | 2.1% | Oct 17, 2017 | Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal K... |
| CVE-2017-13078 | — | — | 2.1% | Oct 17, 2017 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshak... |
| CVE-2017-13077 | — | — | 2.4% | Oct 17, 2017 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during... |
| CVE-2017-15385 | — | — | 1.0% | Oct 16, 2017 | The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause... |
| CVE-2017-9368 | — | — | 1.4% | Oct 16, 2017 | An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access t... |
| CVE-2017-9367 | — | — | 1.6% | Oct 16, 2017 | A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute o... |
| CVE-2017-0316 | HIGH | 7.8 | 0.3% | Oct 16, 2017 | In GeForce Experience (GFE) 3.x before 3.10.0.55, NVIDIA Installer Framework contains a vulnerability in NVISystemServic... |
| CVE-2017-15289 | MEDIUM | 6 | 0.5% | Oct 16, 2017 | The mode4and5 write functions in hw/display/cirrus_vga.c in Qemu allow local OS guest privileged users to cause a denial... |
| CVE-2017-15265 | HIGH | 7 | 0.4% | Oct 16, 2017 | Race condition in the ALSA subsystem in the Linux kernel before 4.13.8 allows local users to cause a denial of service (... |
| CVE-2017-15221 | HIGH | 7.8 | 5.5% | Oct 16, 2017 | ASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324. |
| CVE-2017-15384 | — | — | 1.0% | Oct 16, 2017 | rate-me.php in Rate Me 1.0 has XSS via the id field in a rate action. |
| CVE-2017-15383 | — | — | 0.5% | Oct 16, 2017 | Nero 7.10.1.0 has an unquoted BINARY_PATH_NAME for NBService, exploitable via a Trojan horse Nero.exe file in the %PROGR... |
| CVE-2017-15361 | — | — | 9.8% | Oct 16, 2017 | The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000... |
| CVE-2017-15297 | — | — | 3.0% | Oct 16, 2017 | SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993. |
| CVE-2017-15296 | — | — | 0.5% | Oct 16, 2017 | The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964. |
| CVE-2017-15295 | — | — | 2.4% | Oct 16, 2017 | Xpress Server in SAP POS does not require authentication for read/write/delete file access. This is SAP Security Note 25... |
| CVE-2017-15294 | — | — | 1.0% | Oct 16, 2017 | The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964. |
| CVE-2017-15293 | — | — | 3.9% | Oct 16, 2017 | Xpress Server in SAP POS does not require authentication for file read and erase operations, daemon shutdown, terminal r... |
| CVE-2017-14952 | — | — | 5.1% | Oct 16, 2017 | Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote atta... |
| CVE-2017-15376 | CRITICAL | 9.8 | 3.8% | Oct 16, 2017 | The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute a... |
| CVE-2017-15375 | — | — | 0.9% | Oct 16, 2017 | Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application ... |
| CVE-2017-15374 | — | — | 4.8% | Oct 16, 2017 | Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now