2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-0814An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7....
CVE-2017-0813A denial of service vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 7.0, 7.1....
CVE-2017-0812An elevation of privilege vulnerability in the Android media framework (audio hal). Product: Android. Versions: 7.0, 7.1...
CVE-2017-0811A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1...
CVE-2017-0810A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1,...
CVE-2017-0809A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4...
CVE-2017-0808An information disclosure vulnerability in the Android framework (file system). Product: Android. Versions: 7.0, 7.1.1, ...
CVE-2017-0807An elevation of privilege vulnerability in the Android framework (ui framework). Product: Android. Versions: 4.4.4, 5.0....
CVE-2017-0806An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, ...
CVE-2017-9797When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user a...
CVE-2017-9538The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows rem...
CVE-2017-9537Persistent cross-site scripting (XSS) in the Add Node function of SolarWinds Network Performance Monitor version 12.0.15...
CVE-2017-8021CRITICAL9.8EMC Elastic Cloud Storage (ECS) before 3.1 is affected by an undocumented account vulnerability that could potentially b...
CVE-2017-8018EMC AppSync host plug-in versions 3.5 and below (Windows platform only) includes a denial of service (DoS) vulnerability...
CVE-2017-6090Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica...
CVE-2017-6089SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via...
CVE-2017-1569IBM WebSphere Commerce 7.0 and 8.0 contains an unspecified vulnerability in Marketing ESpot's that could cause a denial ...
CVE-2017-14990WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key...
CVE-2017-14989A use-after-free in RenderFreetype in MagickCore/annotate.c in ImageMagick 7.0.7-4 Q16 allows attackers to crash the app...
CVE-2017-14988Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote attackers to cause a denial of service (excessiv...
CVE-2017-14985Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticat...
CVE-2017-14984Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticat...
CVE-2017-14983Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticat...
CVE-2017-14981Cross-Site Scripting (XSS) was discovered in ATutor before 2.2.3. The vulnerability exists due to insufficient filtratio...
CVE-2017-14979Gxlcms uses an unsafe character-replacement approach in an attempt to restrict access, which allows remote attackers to ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now