2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-0814 | — | — | 1.0% | Oct 4, 2017 | An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.... |
| CVE-2017-0813 | — | — | 0.9% | Oct 4, 2017 | A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1.... |
| CVE-2017-0812 | — | — | 0.5% | Oct 4, 2017 | An elevation of privilege vulnerability in the Android media framework (audio hal). Product: Android. Versions: 7.0, 7.1... |
| CVE-2017-0811 | — | — | 1.5% | Oct 4, 2017 | A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1... |
| CVE-2017-0810 | — | — | 1.5% | Oct 4, 2017 | A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1,... |
| CVE-2017-0809 | — | — | 1.3% | Oct 4, 2017 | A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4... |
| CVE-2017-0808 | — | — | 0.6% | Oct 4, 2017 | An information disclosure vulnerability in the Android framework (file system). Product: Android. Versions: 7.0, 7.1.1, ... |
| CVE-2017-0807 | — | — | 1.9% | Oct 4, 2017 | An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0.... |
| CVE-2017-0806 | — | — | 1.1% | Oct 4, 2017 | An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, ... |
| CVE-2017-9797 | — | — | 1.4% | Oct 3, 2017 | When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user a... |
| CVE-2017-9538 | — | — | 2.4% | Oct 3, 2017 | The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows rem... |
| CVE-2017-9537 | — | — | 2.8% | Oct 3, 2017 | Persistent cross-site scripting (XSS) in the Add Node function of SolarWinds Network Performance Monitor version 12.0.15... |
| CVE-2017-8021 | CRITICAL | 9.8 | 2.1% | Oct 3, 2017 | EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially b... |
| CVE-2017-8018 | — | — | 1.4% | Oct 3, 2017 | EMC AppSync host plug-in versions 3.5 and below (Windows platform only) includes a denial of service (DoS) vulnerability... |
| CVE-2017-6090 | — | — | 96.1% | Oct 3, 2017 | Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica... |
| CVE-2017-6089 | — | — | 3.0% | Oct 3, 2017 | SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via... |
| CVE-2017-1569 | — | — | 1.8% | Oct 3, 2017 | IBM WebSphere Commerce 7.0 and 8.0 contains an unspecified vulnerability in Marketing ESpot's that could cause a denial ... |
| CVE-2017-14990 | — | — | 1.8% | Oct 3, 2017 | WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key... |
| CVE-2017-14989 | — | — | 1.5% | Oct 3, 2017 | A use-after-free in RenderFreetype in MagickCore/annotate.c in ImageMagick 7.0.7-4 Q16 allows attackers to crash the app... |
| CVE-2017-14988 | — | — | 1.0% | Oct 3, 2017 | Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote attackers to cause a denial of service (excessiv... |
| CVE-2017-14985 | — | — | 0.8% | Oct 3, 2017 | Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticat... |
| CVE-2017-14984 | — | — | 0.8% | Oct 3, 2017 | Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticat... |
| CVE-2017-14983 | — | — | 0.8% | Oct 3, 2017 | Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticat... |
| CVE-2017-14981 | — | — | 0.6% | Oct 3, 2017 | Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtratio... |
| CVE-2017-14979 | — | — | 1.5% | Oct 3, 2017 | Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now