2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2017-8063HIGH7.8drivers/media/usb/dvb-usb/cxusb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CON...
CVE-2017-8062HIGH7.8drivers/media/usb/dvb-usb/dw2102.c in the Linux kernel 4.9.x and 4.10.x before 4.10.4 interacts incorrectly with the CON...
CVE-2017-5156HIGH8.8A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5...
CVE-2017-2784HIGH8.1An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before ...
CVE-2017-7961HIGH7.8The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable v...
CVE-2017-7645HIGH7.5The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a deni...
CVE-2017-7889HIGH7.8The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism...
CVE-2017-7615HIGH8.8MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value ...
CVE-2017-7717HIGH8.8SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allo...
CVE-2017-7690HIGH7.8Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary w...
CVE-2017-7643HIGH7.8Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid progra...
CVE-2017-7408HIGH7.5Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper v...
CVE-2017-6059HIGH7.5Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2....
CVE-2017-0210HIGH8.8An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, w...
CVE-2017-0199HIGH7.8Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window...
CVE-2017-7618HIGH7.5crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling i...
CVE-2017-7605HIGH7.8aacplusenc.c in HE-AAC+ Codec (aka libaacplus) 2.0.2 has an assertion failure, which might allow remote attackers to cau...
CVE-2017-7604HIGH7.8au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a left-shift undefined behavior issue, which might allow remote...
CVE-2017-7603HIGH7.8au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a signed integer overflow, which might allow remote attackers t...
CVE-2017-4964HIGH8.8Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary ...
CVE-2017-3832HIGH7.5A vulnerability in the web management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthent...
CVE-2017-7571HIGH8public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
CVE-2017-6884HIGH8.8A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vul...
CVE-2017-3204HIGH8.1The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default ...
CVE-2017-7412HIGH7.8NixOS 17.03 before 17.03.887 has a world-writable Docker socket, which allows local users to gain privileges by executin...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now