2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-0222 | HIGH | 8.8 | 29.6% | May 12, 2017 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet... |
| CVE-2017-0213 | HIGH | 7.3 | 84.1% | May 12, 2017 | Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser... |
| CVE-2017-8912 | HIGH | 7.2 | 3.1% | May 12, 2017 | CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code para... |
| CVE-2017-8890 | HIGH | 7.8 | 1.4% | May 10, 2017 | The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers... |
| CVE-2017-3074 | HIGH | 8.8 | 5.0% | May 9, 2017 | Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Graphics c... |
| CVE-2017-3073 | HIGH | 8.8 | 4.9% | May 9, 2017 | Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when handling multip... |
| CVE-2017-3072 | HIGH | 8.8 | 5.0% | May 9, 2017 | Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BitmapData... |
| CVE-2017-3071 | HIGH | 8.8 | 6.2% | May 9, 2017 | Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable use after free vulnerability when masking display... |
| CVE-2017-3070 | HIGH | 8.8 | 5.0% | May 9, 2017 | Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Convolutio... |
| CVE-2017-3069 | HIGH | 8.8 | 5.0% | May 9, 2017 | Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the BlendMode ... |
| CVE-2017-3068 | HIGH | 8.8 | 20.4% | May 9, 2017 | Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced V... |
| CVE-2017-8844 | HIGH | 7.8 | 1.6% | May 8, 2017 | The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (hea... |
| CVE-2017-3731 | HIGH | 7.5 | 57.6% | May 4, 2017 | If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet... |
| CVE-2017-8776 | HIGH | 7.5 | 0.9% | May 4, 2017 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 h... |
| CVE-2017-6625 | HIGH | 7.1 | 1.8% | May 3, 2017 | A "Cisco Firepower Threat Defense 6.0.0 through 6.2.2 and Cisco ASA with FirePOWER Module Denial of Service" vulnerabili... |
| CVE-2017-7483 | HIGH | 7.5 | 2.1% | May 2, 2017 | Rxvt 2.7.10 is vulnerable to a denial of service attack by passing the value -2^31 inside a terminal escape code, which ... |
| CVE-2017-8114 | HIGH | 8.8 | 3.5% | Apr 29, 2017 | Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x be... |
| CVE-2017-7957 | HIGH | 7.5 | 5.1% | Apr 29, 2017 | XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the... |
| CVE-2017-2130 | HIGH | 7.8 | 1.7% | Apr 28, 2017 | Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer version Ver. 3.7.13 and earli... |
| CVE-2017-2097 | HIGH | 8.8 | 0.7% | Apr 28, 2017 | Cross-site request forgery (CSRF) vulnerability in Knowledge versions prior to v1.7.0 allows remote attackers to hijack ... |
| CVE-2017-8291 | HIGH | 7.8 | 97.0% | Apr 27, 2017 | Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion ... |
| CVE-2017-6054 | HIGH | 7.5 | 2.1% | Apr 26, 2017 | A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. The appli... |
| CVE-2017-7477 | HIGH | 7 | 0.4% | Apr 25, 2017 | Heap-based buffer overflow in drivers/net/macsec.c in the MACsec module in the Linux kernel through 4.10.12 allows attac... |
| CVE-2017-5043 | HIGH | 8.8 | 1.3% | Apr 24, 2017 | Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, wh... |
| CVE-2017-5039 | HIGH | 7.8 | 1.0% | Apr 24, 2017 | A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Andr... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now