2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7374 | HIGH | 7.8 | 0.8% | Mar 31, 2017 | Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of ser... |
| CVE-2017-2775 | HIGH | 7.5 | 2.9% | Mar 31, 2017 | An exploitable memory corruption vulnerability exists in the LvVariantUnflatten functionality in 64-bit versions of LabV... |
| CVE-2017-7323 | HIGH | 8.1 | 2.1% | Mar 30, 2017 | The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by... |
| CVE-2017-7322 | HIGH | 8.1 | 1.2% | Mar 30, 2017 | The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certifi... |
| CVE-2017-7308 | HIGH | 7.8 | 17.8% | Mar 29, 2017 | The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer... |
| CVE-2017-7294 | HIGH | 7.8 | 0.4% | Mar 29, 2017 | The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.6 does... |
| CVE-2017-7297 | HIGH | 8.8 | 1.5% | Mar 29, 2017 | Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This i... |
| CVE-2017-6964 | HIGH | 7.8 | 0.5% | Mar 28, 2017 | dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) set... |
| CVE-2017-6458 | HIGH | 8.8 | 6.5% | Mar 27, 2017 | Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenti... |
| CVE-2017-5931 | HIGH | 8.8 | 0.5% | Mar 27, 2017 | Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cau... |
| CVE-2017-5510 | HIGH | 7.8 | 2.3% | Mar 24, 2017 | coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an... |
| CVE-2017-5509 | HIGH | 7.8 | 1.7% | Mar 24, 2017 | coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an... |
| CVE-2017-5507 | HIGH | 7.5 | 6.0% | Mar 24, 2017 | Memory leak in coders/mpc.c in ImageMagick before 6.9.7-4 and 7.x before 7.0.4-4 allows remote attackers to cause a deni... |
| CVE-2017-5506 | HIGH | 7.8 | 2.1% | Mar 24, 2017 | Double free vulnerability in magick/profile.c in ImageMagick allows remote attackers to have unspecified impact via a cr... |
| CVE-2017-6369 | HIGH | 8.8 | 3.3% | Mar 24, 2017 | Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticate... |
| CVE-2017-3864 | HIGH | 8.6 | 2.7% | Mar 22, 2017 | A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3... |
| CVE-2017-3857 | HIGH | 7.5 | 2.6% | Mar 22, 2017 | A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through 12.4 and 15.0 throu... |
| CVE-2017-6058 | HIGH | 7.5 | 3.9% | Mar 20, 2017 | Buffer overflow in NetRxPkt::ehdr_buf in hw/net/net_rx_pkt.c in QEMU (aka Quick Emulator), when the VLANSTRIP feature is... |
| CVE-2017-7187 | HIGH | 7.8 | 0.4% | Mar 20, 2017 | The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel through 4.10.4 allows local users to cause a denial of se... |
| CVE-2017-7184 | HIGH | 7.8 | 1.8% | Mar 19, 2017 | The xfrm_replay_verify_len function in net/xfrm/xfrm_user.c in the Linux kernel through 4.10.6 does not validate certain... |
| CVE-2017-7178 | HIGH | 8.8 | 4.0% | Mar 18, 2017 | CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted p... |
| CVE-2017-6967 | HIGH | 7.3 | 1.2% | Mar 17, 2017 | xrdp 0.9.1 calls the PAM function auth_start_session() in an incorrect location, leading to PAM session modules not bein... |
| CVE-2017-6960 | HIGH | 7.5 | 1.8% | Mar 17, 2017 | An issue was discovered in apng2gif 1.7. There is an integer overflow resulting in a heap-based buffer over-read, relate... |
| CVE-2017-0149 | HIGH | 8.8 | 29.2% | Mar 17, 2017 | Microsoft Internet Explorer 9 through 11 allow remote attackers to execute arbitrary code or cause a denial of service (... |
| CVE-2017-0148 | HIGH | 8.1 | 99.4% | Mar 17, 2017 | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now