2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-15373E-Sic 1.0 allows SQL injection via the q parameter to esiclivre/restrito/inc/lkpcep.php (aka the search private area).
CVE-2017-15372There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14...
CVE-2017-15371There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A...
CVE-2017-15370There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted i...
CVE-2017-15369The build_filter_chain function in pdf/pdf-stream.c in Artifex MuPDF before 2017-09-25 mishandles a certain case where a...
CVE-2017-15368The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service...
CVE-2017-15362osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/ticket...
CVE-2017-15303In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because...
CVE-2017-15302In CPUID CPU-Z through 1.81, there are improper access rights to a kernel-mode driver (e.g., cpuz143_x64.sys for version...
CVE-2017-15364The foreach function in ext/ccsv.c in Ccsv 1.1.0 allows remote attackers to cause a denial of service (double free and a...
CVE-2017-15363HIGH7.5Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used ...
CVE-2017-15360PRTG Network Monitor version 17.3.33.2830 is vulnerable to stored Cross-Site Scripting on all group names created, relat...
CVE-2017-15300The miner statistics HTTP API in EWBF Cuda Zcash Miner Version 0.3.4b hangs on incoming TCP connections until some sort ...
CVE-2017-15305XSS exists in NexusPHP 1.5 via the keyword parameter to messages.php.
CVE-2017-15304/bin/login.php in the Web Panel on the Airtame HDMI dongle with firmware before 3.0 allows an attacker to set his own se...
CVE-2017-15299The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uni...
CVE-2017-12629CRITICAL9.8Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction wi...
CVE-2017-15298Git through 2.14.2 mishandles layers of tree objects, which allows remote attackers to cause a denial of service (memory...
CVE-2017-6224Ruckus Wireless Zone Director Controller firmware releases ZD9.x, ZD10.0.0.x, ZD10.0.1.x (less than 10.0.1.0.17 MR1 rele...
CVE-2017-6223Ruckus Wireless Zone Director Controller firmware releases ZD9.9.x, ZD9.10.x, ZD9.13.0.x less than 9.13.0.0.232 contain ...
CVE-2017-10624HIGH7.5Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-the-middle type of att...
CVE-2017-10623HIGH7.1Lack of authentication and authorization of cluster messages in Juniper Networks Junos Space may allow a man-in-the-midd...
CVE-2017-10622CRITICAL9.8An authentication bypass vulnerability in Juniper Networks Junos Space Network Management Platform may allow a remote un...
CVE-2017-10621MEDIUM5.3A denial of service vulnerability in telnetd service on Juniper Networks Junos OS allows remote unauthenticated attacker...
CVE-2017-10620HIGH7.4Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now