2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2017-7374HIGH7.8Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of ser...
CVE-2017-2775HIGH7.5An exploitable memory corruption vulnerability exists in the LvVariantUnflatten functionality in 64-bit versions of LabV...
CVE-2017-7323HIGH8.1The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by...
CVE-2017-7322HIGH8.1The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certifi...
CVE-2017-7308HIGH7.8The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer...
CVE-2017-7294HIGH7.8The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.6 does...
CVE-2017-7297HIGH8.8Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This i...
CVE-2017-6964HIGH7.8dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) set...
CVE-2017-6458HIGH8.8Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenti...
CVE-2017-5931HIGH8.8Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cau...
CVE-2017-5510HIGH7.8coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an...
CVE-2017-5509HIGH7.8coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an...
CVE-2017-5507HIGH7.5Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4 allows remote attackers to cause a deni...
CVE-2017-5506HIGH7.8Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a cr...
CVE-2017-6369HIGH8.8Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticate...
CVE-2017-3864HIGH8.6A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3...
CVE-2017-3857HIGH7.5A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through 12.4 and 15.0 throu...
CVE-2017-6058HIGH7.5Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is...
CVE-2017-7187HIGH7.8The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel through 4.10.4 allows local users to cause a denial of se...
CVE-2017-7184HIGH7.8The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain...
CVE-2017-7178HIGH8.8CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted p...
CVE-2017-6967HIGH7.3xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not bein...
CVE-2017-6960HIGH7.5An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, relate...
CVE-2017-0149HIGH8.8Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (...
CVE-2017-0148HIGH8.1The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now