2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-12837Heap-based buffer overflow in the S_regatom function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-R...
CVE-2017-6315Astaro Security Gateway (aka ASG) 7 allows remote attackers to execute arbitrary code via a crafted request to index.plx...
CVE-2017-14033The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows a...
CVE-2017-10784The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allow...
CVE-2017-14581HIGH7.5The Host Control web service in SAP NetWeaver AS JAVA 7.0 through 7.5 allows remote attackers to cause a denial of servi...
CVE-2017-14311The Winring0x32.sys driver in NetMechanica NetDecision 5.8.2 allows local users to gain privileges via a crafted 0x9C402...
CVE-2017-14143The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, wh...
CVE-2017-14142Multiple cross-site scripting (XSS) vulnerabilities in Kaltura before 13.2.0 allow remote attackers to inject arbitrary ...
CVE-2017-14141HIGH7.2The wiki_decode Developer System Helper function in the admin panel in Kaltura before 13.2.0 allows remote attackers to ...
CVE-2017-10700In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system ...
CVE-2017-10931HIGH7.5The ZXR10 1800-2S before v3.00.40 incorrectly restricts the download of the file directory range for WEB users, resultin...
CVE-2017-10930CRITICAL9.8The ZXR10 1800-2S before v3.00.40 incorrectly restricts access to a resource from an unauthorized actor, resulting in or...
CVE-2017-12616When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or ...
CVE-2017-12615HIGH8.1When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati...
CVE-2017-14601Pragyan CMS v3.0 is vulnerable to a Boolean-based SQL injection in cms/admin.lib.php via $_GET['forwhat'], resulting in ...
CVE-2017-14600Pragyan CMS v3.0 is vulnerable to an Error-Based SQL injection in cms/admin.lib.php via $_GET['del_black'], resulting in...
CVE-2017-14597AdminPanel in AfterLogic WebMail 7.7 and Aurora 7.7.5 has XSS via the txtDomainName field to adminpanel/modules/pro/inc/...
CVE-2017-9803Apache Solr's Kerberos plugin can be configured to use delegation tokens, which allows an application to reuse the authe...
CVE-2017-6147In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.1.2-HF1 and 13.0.0, an undisc...
CVE-2017-14580XnView Classic for Windows Version 2.41 allows attackers to execute arbitrary code or cause a denial of service via a cr...
CVE-2017-14579STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, rel...
CVE-2017-14578IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a cra...
CVE-2017-14577STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel...
CVE-2017-14576STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafte...
CVE-2017-14575STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, rel...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now