2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8063 | HIGH | 7.8 | 0.4% | Apr 23, 2017 | drivers/media/usb/dvb-usb/cxusb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CON... |
| CVE-2017-8062 | HIGH | 7.8 | 0.4% | Apr 23, 2017 | drivers/media/usb/dvb-usb/dw2102.c in the Linux kernel 4.9.x and 4.10.x before 4.10.4 interacts incorrectly with the CON... |
| CVE-2017-5156 | HIGH | 8.8 | 1.0% | Apr 20, 2017 | A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5... |
| CVE-2017-2784 | HIGH | 8.1 | 3.4% | Apr 20, 2017 | An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before ... |
| CVE-2017-7961 | HIGH | 7.8 | 2.0% | Apr 19, 2017 | The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable v... |
| CVE-2017-7645 | HIGH | 7.5 | 5.8% | Apr 18, 2017 | The NFSv2/NFSv3 server in the nfsd subsystem in the Linux kernel through 4.10.11 allows remote attackers to cause a deni... |
| CVE-2017-7889 | HIGH | 7.8 | 0.3% | Apr 17, 2017 | The mm subsystem in the Linux kernel through 3.2 does not properly enforce the CONFIG_STRICT_DEVMEM protection mechanism... |
| CVE-2017-7615 | HIGH | 8.8 | 90.9% | Apr 16, 2017 | MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value ... |
| CVE-2017-7717 | HIGH | 8.8 | 1.9% | Apr 14, 2017 | SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allo... |
| CVE-2017-7690 | HIGH | 7.8 | 1.0% | Apr 14, 2017 | Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary w... |
| CVE-2017-7643 | HIGH | 7.8 | 1.0% | Apr 14, 2017 | Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid progra... |
| CVE-2017-7408 | HIGH | 7.5 | 1.9% | Apr 14, 2017 | Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper v... |
| CVE-2017-6059 | HIGH | 7.5 | 5.2% | Apr 12, 2017 | Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.... |
| CVE-2017-0210 | HIGH | 8.8 | 19.5% | Apr 12, 2017 | An elevation of privilege vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, w... |
| CVE-2017-0199 | HIGH | 7.8 | 99.9% | Apr 12, 2017 | Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window... |
| CVE-2017-7618 | HIGH | 7.5 | 4.3% | Apr 10, 2017 | crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling i... |
| CVE-2017-7605 | HIGH | 7.8 | 1.5% | Apr 9, 2017 | aacplusenc.c in HE-AAC+ Codec (aka libaacplus) 2.0.2 has an assertion failure, which might allow remote attackers to cau... |
| CVE-2017-7604 | HIGH | 7.8 | 1.5% | Apr 9, 2017 | au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a left-shift undefined behavior issue, which might allow remote... |
| CVE-2017-7603 | HIGH | 7.8 | 1.5% | Apr 9, 2017 | au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a signed integer overflow, which might allow remote attackers t... |
| CVE-2017-4964 | HIGH | 8.8 | 0.5% | Apr 6, 2017 | Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary ... |
| CVE-2017-3832 | HIGH | 7.5 | 3.2% | Apr 6, 2017 | A vulnerability in the web management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthent... |
| CVE-2017-7571 | HIGH | 8 | 2.2% | Apr 6, 2017 | public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. |
| CVE-2017-6884 | HIGH | 8.8 | 37.6% | Apr 6, 2017 | A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vul... |
| CVE-2017-3204 | HIGH | 8.1 | 3.2% | Apr 4, 2017 | The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default ... |
| CVE-2017-7412 | HIGH | 7.8 | 0.4% | Apr 4, 2017 | NixOS 17.03 before 17.03.887 has a world-writable Docker socket, which allows local users to gain privileges by executin... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now