2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-4903 | HIGH | 8.8 | 0.4% | Jun 7, 2017 | VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi... |
| CVE-2017-4902 | HIGH | 8.8 | 0.5% | Jun 7, 2017 | VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player ... |
| CVE-2017-7564 | HIGH | 7.5 | 1.0% | Jun 7, 2017 | In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to ca... |
| CVE-2017-7563 | HIGH | 8.1 | 0.9% | Jun 7, 2017 | In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_E... |
| CVE-2017-9462 | HIGH | 8.8 | 21.5% | Jun 6, 2017 | In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and conse... |
| CVE-2017-9443 | HIGH | 8.8 | 1.3% | Jun 5, 2017 | BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables objec... |
| CVE-2017-9380 | HIGH | 8.8 | 15.2% | Jun 2, 2017 | OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code... |
| CVE-2017-9334 | HIGH | 7.5 | 1.5% | Jun 1, 2017 | An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Sche... |
| CVE-2017-9250 | HIGH | 7.5 | 2.5% | May 28, 2017 | The lexer_process_char_literal function in jerry-core/parser/js/js-lexer.c in JerryScript 1.0 does not skip memory alloc... |
| CVE-2017-8540 | HIGH | 7.8 | 72.0% | May 26, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve... |
| CVE-2017-9036 | HIGH | 7.8 | 0.5% | May 26, 2017 | Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestrict... |
| CVE-2017-9035 | HIGH | 7.4 | 3.6% | May 26, 2017 | Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveragi... |
| CVE-2017-9033 | HIGH | 8.8 | 2.3% | May 26, 2017 | Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote ... |
| CVE-2017-9230 | HIGH | 7.5 | 3.3% | May 24, 2017 | The Bitcoin Proof-of-Work algorithm does not consider a certain attack methodology related to 80-byte block headers with... |
| CVE-2017-9229 | HIGH | 7.5 | 5.1% | May 24, 2017 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7... |
| CVE-2017-2823 | HIGH | 7.8 | 9.4% | May 24, 2017 | A use-after-free vulnerability exists in the .ISO parsing functionality of PowerISO 6.8. A specially crafted .ISO file c... |
| CVE-2017-2819 | HIGH | 8.8 | 1.7% | May 24, 2017 | An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom T... |
| CVE-2017-2817 | HIGH | 8.8 | 1.7% | May 24, 2017 | A stack buffer overflow vulnerability exists in the ISO parsing functionality of Power Software Ltd PowerISO 6.8. A spec... |
| CVE-2017-2799 | HIGH | 8.3 | 1.3% | May 24, 2017 | An exploitable heap corruption vulnerability exists in the AddSst functionality of Antenna House DMC HTMLFilter as used ... |
| CVE-2017-2798 | HIGH | 8.3 | 1.3% | May 24, 2017 | An exploitable heap corruption vulnerability exists in the GetIndexArray functionality of Antenna House DMC HTMLFilter a... |
| CVE-2017-9217 | HIGH | 7.5 | 15.4% | May 24, 2017 | systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS respo... |
| CVE-2017-2797 | HIGH | 8.3 | 0.9% | May 23, 2017 | An exploitable heap overflow vulnerability exists in the ParseEnvironment functionality of AntennaHouse DMC HTMLFilter a... |
| CVE-2017-2794 | HIGH | 8.3 | 1.3% | May 23, 2017 | An exploitable stack-based buffer overflow vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTML... |
| CVE-2017-2793 | HIGH | 8.3 | 1.4% | May 23, 2017 | An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilt... |
| CVE-2017-2783 | HIGH | 8.3 | 1.3% | May 23, 2017 | An exploitable heap corruption vulnerability exists in the FillRowFormat functionality of Antenna House DMC HTMLFilter t... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now