2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7441 | — | — | 0.5% | Sep 13, 2017 | In Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean), a cra... |
| CVE-2017-6008 | — | — | 1.9% | Sep 13, 2017 | A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in ... |
| CVE-2017-6007 | — | — | 0.4% | Sep 13, 2017 | A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in ... |
| CVE-2017-14398 | HIGH | 7.8 | 0.3% | Sep 13, 2017 | rzpnk.sys in Razer Synapse 2.20.15.1104 allows local users to read and write to arbitrary memory locations, and conseque... |
| CVE-2017-13724 | — | — | 0.5% | Sep 13, 2017 | On the Axesstel MU553S MU55XS-V1.14, there is a Stored Cross Site Scripting vulnerability in the APN parameter under the... |
| CVE-2017-11351 | — | — | 1.4% | Sep 13, 2017 | Axesstel MU553S MU55XS-V1.14 devices have a default password of admin for the admin account. |
| CVE-2017-11350 | — | — | 0.4% | Sep 13, 2017 | Cross-Site Request Forgery (CSRF) exists in cgi-bin/ConfigSet on Axesstel MU553S MU55XS-V1.14 devices. |
| CVE-2017-14412 | — | — | 0.8% | Sep 13, 2017 | An invalid memory write was discovered in copy_mp in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vul... |
| CVE-2017-14411 | — | — | 1.6% | Sep 13, 2017 | A stack-based buffer overflow was discovered in copy_mp in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. T... |
| CVE-2017-14410 | — | — | 0.9% | Sep 13, 2017 | A buffer over-read was discovered in III_i_stereo in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulner... |
| CVE-2017-14409 | — | — | 1.6% | Sep 13, 2017 | A buffer overflow was discovered in III_dequantize_sample in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. Th... |
| CVE-2017-14408 | — | — | 0.9% | Sep 13, 2017 | A stack-based buffer over-read was discovered in dct36 in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The v... |
| CVE-2017-14407 | — | — | 0.9% | Sep 13, 2017 | A stack-based buffer over-read was discovered in filterYule in gain_analysis.c in MP3Gain version 1.5.2. The vulnerabili... |
| CVE-2017-14406 | — | — | 0.9% | Sep 13, 2017 | A NULL pointer dereference was discovered in sync_buffer in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. ... |
| CVE-2017-14405 | — | — | 3.5% | Sep 13, 2017 | The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote command execution via shell metacharacters in a hosts_c... |
| CVE-2017-14404 | — | — | 1.5% | Sep 13, 2017 | The EyesOfNetwork web interface (aka eonweb) 5.1-0 allows local file inclusion via the tool_list parameter (aka the url_... |
| CVE-2017-14403 | — | — | 1.5% | Sep 13, 2017 | The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the term parameter to module/admin_group/search... |
| CVE-2017-14402 | — | — | 1.5% | Sep 13, 2017 | The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/ad... |
| CVE-2017-14401 | — | — | 1.5% | Sep 13, 2017 | The EyesOfNetwork web interface (aka eonweb) 5.1-0 has SQL injection via the user_name parameter to module/admin_user/ad... |
| CVE-2017-8759 | HIGH | 7.8 | 88.7% | Sep 13, 2017 | Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi... |
| CVE-2017-8758 | MEDIUM | 6.1 | 3.4% | Sep 13, 2017 | Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access... |
| CVE-2017-8757 | — | — | 16.4% | Sep 13, 2017 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arb... |
| CVE-2017-8756 | — | — | 8.7% | Sep 13, 2017 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arb... |
| CVE-2017-8755 | — | — | 71.3% | Sep 13, 2017 | Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary... |
| CVE-2017-8754 | — | — | 3.5% | Sep 13, 2017 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a use... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now