2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-12798Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the q parameter to searchsuggest.php.
CVE-2017-1431IBM InfoSphere Streams 4.0, 4.1, and 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed...
CVE-2017-1377IBM Runbook Automation reveals sensitive information in error messages that could be used in further attacks against the...
CVE-2017-1192IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data....
CVE-2017-1174IBM Sterling B2B Integrator Standard Edition 5.2 is vulnerable to SQL injection. A remote attacker could send specially-...
CVE-2017-1168IBM Rational Engineering Lifecycle Manager 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability a...
CVE-2017-3753A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, ...
CVE-2017-3751An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoin...
CVE-2017-9799It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it i...
CVE-2017-3752An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing ...
CVE-2017-12777Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.
CVE-2017-12774finecms in 1.9.5\controllers\member\ContentController.php allows remote attackers to operate website database
CVE-2017-12762CRITICAL9.8In /drivers/isdn/i4l/isdn_net.c: A user-controlled buffer is copied into a local buffer of constant size using strcpy wi...
CVE-2017-12756Command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the us...
CVE-2017-0750A elevation of privilege vulnerability in the Upstream Linux file system. Product: Android. Versions: Android kernel. An...
CVE-2017-0749A elevation of privilege vulnerability in the Upstream Linux linux kernel. Product: Android. Versions: Android kernel. A...
CVE-2017-0747A elevation of privilege vulnerability in the Qualcomm proprietary component. Product: Android. Versions: Android kernel...
CVE-2017-0746A elevation of privilege vulnerability in the Qualcomm ipa driver. Product: Android. Versions: Android kernel. Android I...
CVE-2017-0745A remote code execution vulnerability in the Android media framework (avc decoder). Product: Android. Versions: 4.4.4, 5...
CVE-2017-0742A elevation of privilege vulnerability in the MediaTek video driver. Product: Android. Versions: Android kernel. Android...
CVE-2017-0741A elevation of privilege vulnerability in the MediaTek gpu driver. Product: Android. Versions: Android kernel. Android I...
CVE-2017-0740A remote code execution vulnerability in the Broadcom networking driver. Product: Android. Versions: Android kernel. And...
CVE-2017-0739A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1....
CVE-2017-0738A information disclosure vulnerability in the Android media framework (audioserver). Product: Android. Versions: 4.4.4, ...
CVE-2017-0737A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4....

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now