2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-8665The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin...
CVE-2017-12864HIGH8.8In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function ReadNumber did not checkout the input length, which lead to inte...
CVE-2017-12863HIGH8.8In opencv/modules/imgcodecs/src/grfmt_pxm.cpp, function PxMDecoder::readData has an integer overflow when calculate src_...
CVE-2017-12862HIGH8.8In modules/imgcodecs/src/grfmt_pxm.cpp, the length of buffer AutoBuffer _src is small than expected, which will cause co...
CVE-2017-12855Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expect...
CVE-2017-12852The numpy.pad function in Numpy 1.13.1 and older versions is missing input validation. An empty list or ndarray will sti...
CVE-2017-1469IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing ar...
CVE-2017-1190IBM Emptoris Strategic Supply Management Platform 10.x and 10.1 could allow a local user with special access roles to ex...
CVE-2017-12426GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x...
CVE-2017-12853The RealTime RWR-3G-100 Router Firmware Version : Ver1.0.56 is affected by CSRF an attack that forces an end user to exe...
CVE-2017-12851An authenticated standard user could reset the password of the admin by altering form data. Affects kanboard before 1.0....
CVE-2017-12850An authenticated standard user could reset the password of other users (including the admin) by altering form data. Affe...
CVE-2017-11156Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsear...
CVE-2017-11150Command injection vulnerability in Document.php in Synology Office 2.2.0-1502 and 2.2.1-1506 allows remote authenticated...
CVE-2017-11149Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and ...
CVE-2017-9662An Improper Privilege Management issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43....
CVE-2017-9661An Uncontrolled Search Path Element issue was discovered in SIMPlight SCADA Software version 4.3.0.27 and prior. The unc...
CVE-2017-9660A Heap-Based Buffer Overflow was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. A heap-...
CVE-2017-9659A Stack-Based Buffer Overflow issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. ...
CVE-2017-9655A Cross-Site Scripting issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integrato...
CVE-2017-9653An Improper Authorization issue was discovered in OSIsoft PI Integrator for Business Analytics before 2016 R2, PI Integr...
CVE-2017-9648An Uncontrolled Search Path Element issue was discovered in Solar Controls WATTConfig M Software Version 2.5.10.1 and pr...
CVE-2017-9646An Uncontrolled Search Path Element issue was discovered in Solar Controls Heating Control Downloader (HCDownloader) Ver...
CVE-2017-9802The Javascript method Sling.evalString() in Apache Sling Servlets Post before 2.3.22 uses the javascript 'eval' function...
CVE-2017-12807Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-12799. Reason: This candidate is a reservation d...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now