2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-13729 | MEDIUM | 6.5 | 2.9% | Aug 29, 2017 | There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remot... |
| CVE-2017-13728 | HIGH | 7.5 | 3.9% | Aug 29, 2017 | There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input wi... |
| CVE-2017-13727 | — | — | 2.3% | Aug 29, 2017 | There is a reachable assertion abort in the function TIFFWriteDirectoryTagSubifd() in LibTIFF 4.0.8, related to tif_dirw... |
| CVE-2017-13726 | — | — | 2.6% | Aug 29, 2017 | There is a reachable assertion abort in the function TIFFWriteDirectorySec() in LibTIFF 4.0.8, related to tif_dirwrite.c... |
| CVE-2017-13685 | — | — | 1.8% | Aug 29, 2017 | The dump_callback function in SQLite 3.20.0 allows remote attackers to cause a denial of service (EXC_BAD_ACCESS and app... |
| CVE-2017-3757 | — | — | 0.4% | Aug 29, 2017 | An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on... |
| CVE-2017-3746 | — | — | 0.4% | Aug 29, 2017 | ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege es... |
| CVE-2017-2258 | — | — | 1.3% | Aug 29, 2017 | Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon ... |
| CVE-2017-2257 | — | — | 0.7% | Aug 29, 2017 | Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or ... |
| CVE-2017-2256 | — | — | 0.5% | Aug 29, 2017 | Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or ... |
| CVE-2017-2255 | — | — | 0.5% | Aug 29, 2017 | Cross-site scripting vulnerability in Cybozu Garoon 3.7.0 to 4.2.5 allows an attacker to inject arbitrary web script or ... |
| CVE-2017-2254 | — | — | 1.1% | Aug 29, 2017 | Cybozu Garoon 3.5.0 to 4.2.5 allows an attacker to cause a denial of service in the application menu's edit function via... |
| CVE-2017-2242 | — | — | 1.1% | Aug 29, 2017 | Untrusted search path vulnerability in Flets Setsuzoku Tool for Windows all versions allows an attacker to gain privileg... |
| CVE-2017-1489 | — | — | 1.2% | Aug 29, 2017 | IBM Security Access Manager 6.1, 7.0, 8.0, and 9.0 e-community configurations may be affected by a redirect vulnerabilit... |
| CVE-2017-1376 | — | — | 2.6% | Aug 29, 2017 | A flaw in the IBM J9 VM class verifier allows untrusted code to disable the security manager and elevate its privileges.... |
| CVE-2017-13715 | CRITICAL | 9.8 | 9.7% | Aug 29, 2017 | The __skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel before 4.3 does not ensure that n_proto... |
| CVE-2017-1110 | — | — | 1.0% | Aug 29, 2017 | IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an aut... |
| CVE-2017-10844 | — | — | 1.5% | Aug 29, 2017 | baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspec... |
| CVE-2017-10843 | — | — | 1.4% | Aug 29, 2017 | baserCMS version 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to delete arbitrary files via unspecified... |
| CVE-2017-10842 | — | — | 1.8% | Aug 29, 2017 | SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arb... |
| CVE-2017-10841 | — | — | 2.4% | Aug 29, 2017 | Directory traversal vulnerability in WebCalendar 1.2.7 and earlier allows authenticated attackers to read arbitrary file... |
| CVE-2017-10840 | — | — | 0.9% | Aug 29, 2017 | Cross-site scripting vulnerability in WebCalendar 1.2.7 and earlier allows an attacker to inject arbitrary web script or... |
| CVE-2017-10839 | — | — | 1.1% | Aug 29, 2017 | SQL injection vulnerability in the SEO Panel prior to version 3.11.0 allows authenticated attackers to execute arbitrary... |
| CVE-2017-10838 | — | — | 0.7% | Aug 29, 2017 | Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web scrip... |
| CVE-2017-10837 | MEDIUM | 6.1 | 0.9% | Aug 29, 2017 | Cross-site scripting vulnerability in BackupGuard prior to version 1.1.47 allows an attacker to inject arbitrary web scr... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now