2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-2827 | HIGH | 8.8 | 7.8% | Jun 21, 2017 | An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Ca... |
| CVE-2017-7668 | HIGH | 7.5 | 57.5% | Jun 20, 2017 | The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which al... |
| CVE-2017-3214 | HIGH | 7.5 | 0.6% | Jun 20, 2017 | The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary. |
| CVE-2017-1000379 | HIGH | 7.8 | 1.8% | Jun 19, 2017 | The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where ... |
| CVE-2017-1000376 | HIGH | 7 | 0.5% | Jun 19, 2017 | libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting th... |
| CVE-2017-1000371 | HIGH | 7.8 | 2.4% | Jun 19, 2017 | The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1... |
| CVE-2017-1000370 | HIGH | 7.8 | 2.3% | Jun 19, 2017 | The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit... |
| CVE-2017-1000365 | HIGH | 7.8 | 0.9% | Jun 19, 2017 | The Linux Kernel imposes a size restriction on the arguments and environmental strings passed through RLIMIT_STACK/RLIM_... |
| CVE-2017-9735 | HIGH | 7.5 | 5.8% | Jun 16, 2017 | Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attack... |
| CVE-2017-8461 | HIGH | 7.8 | 21.1% | Jun 15, 2017 | Windows RPC with Routing and Remote Access enabled in Windows XP and Windows Server 2003 allows an attacker to execute c... |
| CVE-2017-8464 | HIGH | 8.8 | 90.0% | Jun 15, 2017 | Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201... |
| CVE-2017-4981 | HIGH | 7.5 | 1.5% | Jun 14, 2017 | EMC RSA BSAFE Cert-C before 2.9.0.5 contains a potential improper certificate processing vulnerability. |
| CVE-2017-8907 | HIGH | 8.8 | 1.6% | Jun 14, 2017 | Atlassian Bamboo 5.x before 5.15.7 and 6.x before 6.0.1 did not correctly check if a user creating a deployment project ... |
| CVE-2017-2810 | HIGH | 7.5 | 4.9% | Jun 14, 2017 | An exploitable vulnerability exists in the Databook loading functionality of Tablib 0.11.4. A yaml loaded Databook can e... |
| CVE-2017-4991 | HIGH | 7.2 | 0.9% | Jun 13, 2017 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to... |
| CVE-2017-4972 | HIGH | 7.5 | 1.1% | Jun 13, 2017 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to... |
| CVE-2017-4966 | HIGH | 7.8 | 0.4% | Jun 13, 2017 | An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions p... |
| CVE-2017-9557 | HIGH | 7.5 | 1.7% | Jun 12, 2017 | register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sendi... |
| CVE-2017-9543 | HIGH | 7.5 | 1.3% | Jun 12, 2017 | register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords v... |
| CVE-2017-9527 | HIGH | 7.8 | 1.0% | Jun 11, 2017 | The mark_context_stack function in gc.c in mruby through 1.2.0 allows attackers to cause a denial of service (heap-based... |
| CVE-2017-9023 | HIGH | 7.5 | 2.3% | Jun 8, 2017 | The ASN.1 parser in strongSwan before 5.5.3 improperly handles CHOICE types when the x509 plugin is enabled, which allow... |
| CVE-2017-9022 | HIGH | 7.5 | 2.0% | Jun 8, 2017 | The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which ... |
| CVE-2017-7180 | HIGH | 7.3 | 1.1% | Jun 8, 2017 | Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its ... |
| CVE-2017-7965 | HIGH | 7.3 | 0.4% | Jun 7, 2017 | A buffer overflow vulnerability exists in Programming Software executable AlTracePrint.exe, in Schneider Electric's SoMa... |
| CVE-2017-4904 | HIGH | 8.8 | 0.4% | Jun 7, 2017 | The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now