2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-13729MEDIUM6.5There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remot...
CVE-2017-13728HIGH7.5There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input wi...
CVE-2017-13727There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirw...
CVE-2017-13726There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c...
CVE-2017-13685The dump_callback function in SQLite 3.20.0 allows remote attackers to cause a denial of service (EXC_BAD_ACCESS and app...
CVE-2017-3757An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on...
CVE-2017-3746ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege es...
CVE-2017-2258Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon ...
CVE-2017-2257Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or ...
CVE-2017-2256Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or ...
CVE-2017-2255Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or ...
CVE-2017-2254Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via...
CVE-2017-2242Untrusted search path vulnerability in Flets Setsuzoku Tool for Windows all versions allows an attacker to gain privileg...
CVE-2017-1489IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerabilit...
CVE-2017-1376A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges....
CVE-2017-13715CRITICAL9.8The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto...
CVE-2017-1110IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an aut...
CVE-2017-10844baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspec...
CVE-2017-10843baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified...
CVE-2017-10842SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arb...
CVE-2017-10841Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary file...
CVE-2017-10840Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or...
CVE-2017-10839SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary...
CVE-2017-10838Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web scrip...
CVE-2017-10837MEDIUM6.1Cross-site scripting vulnerability in BackupGuard prior to version 1.1.47 allows an attacker to inject arbitrary web scr...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now