2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8665 | — | — | 4.3% | Aug 15, 2017 | The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin... |
| CVE-2017-12864 | HIGH | 8.8 | 2.7% | Aug 15, 2017 | In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to inte... |
| CVE-2017-12863 | HIGH | 8.8 | 2.7% | Aug 15, 2017 | In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function PxMDecoder::readData has an integer overflow when calculate src_... |
| CVE-2017-12862 | HIGH | 8.8 | 3.1% | Aug 15, 2017 | In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected, which will cause co... |
| CVE-2017-12855 | — | — | 0.4% | Aug 15, 2017 | Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expect... |
| CVE-2017-12852 | — | — | 2.7% | Aug 15, 2017 | The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will sti... |
| CVE-2017-1469 | — | — | 0.4% | Aug 14, 2017 | IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing ar... |
| CVE-2017-1190 | — | — | 0.3% | Aug 14, 2017 | IBM Emptoris Strategic Supply Management Platform 10.x and 10.1 could allow a local user with special access roles to ex... |
| CVE-2017-12426 | — | — | 3.5% | Aug 14, 2017 | GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x... |
| CVE-2017-12853 | — | — | 0.9% | Aug 14, 2017 | The RealTime RWR-3G-100 Router Firmware Version : Ver1.0.56 is affected by CSRF an attack that forces an end user to exe... |
| CVE-2017-12851 | — | — | 1.3% | Aug 14, 2017 | An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0.... |
| CVE-2017-12850 | — | — | 1.3% | Aug 14, 2017 | An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affe... |
| CVE-2017-11156 | — | — | 2.2% | Aug 14, 2017 | Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsear... |
| CVE-2017-11150 | — | — | 1.5% | Aug 14, 2017 | Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated... |
| CVE-2017-11149 | — | — | 1.6% | Aug 14, 2017 | Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and ... |
| CVE-2017-9662 | — | — | 0.4% | Aug 14, 2017 | An Improper Privilege Management issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.... |
| CVE-2017-9661 | — | — | 1.4% | Aug 14, 2017 | An Uncontrolled Search Path Element issue was discovered in SIMPlight SCADA Software version 4.3.0.27 and prior. The unc... |
| CVE-2017-9660 | — | — | 5.1% | Aug 14, 2017 | A Heap-Based Buffer Overflow was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. A heap-... |
| CVE-2017-9659 | — | — | 5.2% | Aug 14, 2017 | A Stack-Based Buffer Overflow issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. ... |
| CVE-2017-9655 | — | — | 0.9% | Aug 14, 2017 | A Cross-Site Scripting issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrato... |
| CVE-2017-9653 | — | — | 2.3% | Aug 14, 2017 | An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integr... |
| CVE-2017-9648 | — | — | 1.8% | Aug 14, 2017 | An Uncontrolled Search Path Element issue was discovered in Solar Controls WATTConfig M Software Version 2.5.10.1 and pr... |
| CVE-2017-9646 | — | — | 1.8% | Aug 14, 2017 | An Uncontrolled Search Path Element issue was discovered in Solar Controls Heating Control Downloader (HCDownloader) Ver... |
| CVE-2017-9802 | — | — | 3.2% | Aug 14, 2017 | The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function... |
| CVE-2017-12807 | — | — | — | Aug 14, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-12799. Reason: This candidate is a reservation d... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now