2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8913 | HIGH | 8.8 | 1.4% | May 23, 2017 | The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML ... |
| CVE-2017-8309 | HIGH | 7.5 | 4.5% | May 23, 2017 | Memory leak in the audio/audio.c in QEMU (aka Quick Emulator) allows remote attackers to cause a denial of service (memo... |
| CVE-2017-6891 | HIGH | 8.8 | 5.6% | May 22, 2017 | Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to... |
| CVE-2017-6632 | HIGH | 7.5 | 2.4% | May 22, 2017 | A vulnerability in the logging configuration of Secure Sockets Layer (SSL) policies for Cisco FirePOWER System Software ... |
| CVE-2017-9024 | HIGH | 7.5 | 12.2% | May 21, 2017 | Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Tra... |
| CVE-2017-9100 | HIGH | 8.8 | 85.5% | May 21, 2017 | login.cgi on D-Link DIR-600M devices with firmware 3.04 allows remote attackers to bypass authentication by entering mor... |
| CVE-2017-9098 | HIGH | 7.5 | 3.6% | May 19, 2017 | ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an att... |
| CVE-2017-9078 | HIGH | 8.8 | 5.1% | May 19, 2017 | The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double fre... |
| CVE-2017-9077 | HIGH | 7.8 | 0.7% | May 19, 2017 | The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, whic... |
| CVE-2017-9076 | HIGH | 7.8 | 0.4% | May 19, 2017 | The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, whi... |
| CVE-2017-9075 | HIGH | 7.8 | 0.4% | May 19, 2017 | The sctp_v6_create_accept_sk function in net/sctp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, whic... |
| CVE-2017-9074 | HIGH | 7.8 | 0.4% | May 19, 2017 | The IPv6 fragmentation implementation in the Linux kernel through 4.11.1 does not consider that the nexthdr field may be... |
| CVE-2017-9050 | HIGH | 7.5 | 4.6% | May 18, 2017 | libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictAddString function in d... |
| CVE-2017-9049 | HIGH | 7.5 | 4.6% | May 18, 2017 | libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a heap-based buffer over-read in the xmlDictComputeFastKey function... |
| CVE-2017-9048 | HIGH | 7.5 | 4.9% | May 18, 2017 | libxml2 20904-GITv2.9.4-16-g0741801 is vulnerable to a stack-based buffer overflow. The function xmlSnprintfElementConte... |
| CVE-2017-7493 | HIGH | 7.8 | 0.4% | May 17, 2017 | Quick Emulator (Qemu) built with the VirtFS, host directory sharing via Plan 9 File System(9pfs) support, is vulnerable ... |
| CVE-2017-8927 | HIGH | 7.8 | 3.0% | May 15, 2017 | Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified ... |
| CVE-2017-8928 | HIGH | 8.8 | 2.0% | May 14, 2017 | mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF. |
| CVE-2017-7487 | HIGH | 7.8 | 0.4% | May 14, 2017 | The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allo... |
| CVE-2017-8246 | HIGH | 7.8 | 0.2% | May 12, 2017 | In function msm_pcm_playback_close() in all Android releases from CAF using the Linux kernel, prtd is assigned substream... |
| CVE-2017-8245 | HIGH | 7.8 | 0.2% | May 12, 2017 | In all Android releases from CAF using the Linux kernel, while processing a voice SVC request which is nonstandard by sp... |
| CVE-2017-8244 | HIGH | 7 | 0.1% | May 12, 2017 | In core_info_read and inst_info_read in all Android releases from CAF using the Linux kernel, variable "dbg_buf", "dbg_b... |
| CVE-2017-0263 | HIGH | 7.8 | 10.0% | May 12, 2017 | The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012... |
| CVE-2017-0262 | HIGH | 7.8 | 80.7% | May 12, 2017 | Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar... |
| CVE-2017-0261 | HIGH | 7.8 | 78.1% | May 12, 2017 | Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 allow a remote code execution vulnerability when the softwar... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now