2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-10984 | — | — | 18.3% | Jul 17, 2017 | An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attac... |
| CVE-2017-10983 | — | — | 2.5% | Jul 17, 2017 | An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding opti... |
| CVE-2017-10982 | — | — | 2.9% | Jul 17, 2017 | An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a de... |
| CVE-2017-10981 | — | — | 2.6% | Jul 17, 2017 | An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in fr_dhcp_decode()" and a denial of servi... |
| CVE-2017-10980 | — | — | 3.3% | Jul 17, 2017 | An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in decode_tlv()" and a denial of service. |
| CVE-2017-10979 | — | — | 22.2% | Jul 17, 2017 | An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attack... |
| CVE-2017-10978 | — | — | 3.0% | Jul 17, 2017 | An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()"... |
| CVE-2017-11367 | — | — | 1.5% | Jul 17, 2017 | The shoco_decompress function in the API in shoco through 2017-07-17 allows remote attackers to cause a denial of servic... |
| CVE-2017-10988 | — | — | — | Jul 17, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-8034 | — | — | 0.8% | Jul 17, 2017 | The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions ... |
| CVE-2017-8011 | CRITICAL | 9.8 | 14.0% | Jul 17, 2017 | EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to 4.1, EMC Storage M&R p... |
| CVE-2017-8006 | — | — | 2.1% | Jul 17, 2017 | In EMC RSA Authentication Manager 8.2 SP1 Patch 1 and earlier, a malicious user logged into the Self-Service Console of ... |
| CVE-2017-8005 | — | — | 1.2% | Jul 17, 2017 | The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance, and RSA IMG products (RSA Identity Gove... |
| CVE-2017-8004 | — | — | 2.1% | Jul 17, 2017 | The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Gover... |
| CVE-2017-8000 | — | — | 0.9% | Jul 17, 2017 | In EMC RSA Authentication Manager 8.2 SP1 and earlier, a malicious RSA Security Console Administrator could craft a toke... |
| CVE-2017-9951 | — | — | 4.2% | Jul 17, 2017 | The try_read_command function in memcached.c in memcached before 1.4.39 allows remote attackers to cause a denial of ser... |
| CVE-2017-9814 | HIGH | 7.5 | 3.5% | Jul 17, 2017 | cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds ... |
| CVE-2017-7688 | — | — | 3.0% | Jul 17, 2017 | Apache OpenMeetings 1.0.0 updates user password in insecure manner. |
| CVE-2017-7685 | — | — | 2.9% | Jul 17, 2017 | Apache OpenMeetings 1.0.0 responds to the following insecure HTTP methods: PUT, DELETE, HEAD, and PATCH. |
| CVE-2017-7684 | — | — | 2.8% | Jul 17, 2017 | Apache OpenMeetings 1.0.0 doesn't check contents of files being uploaded. An attacker can cause a denial of service by u... |
| CVE-2017-7683 | — | — | 2.0% | Jul 17, 2017 | Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure. |
| CVE-2017-7682 | — | — | 1.6% | Jul 17, 2017 | Apache OpenMeetings 3.2.0 is vulnerable to parameter manipulation attacks, as a result attacker has access to restricted... |
| CVE-2017-7681 | — | — | 1.3% | Jul 17, 2017 | Apache OpenMeetings 1.0.0 is vulnerable to SQL injection. This allows authenticated users to modify the structure of the... |
| CVE-2017-7680 | — | — | 1.8% | Jul 17, 2017 | Apache OpenMeetings 1.0.0 has an overly permissive crossdomain.xml file. This allows for flash content to be loaded from... |
| CVE-2017-7673 | — | — | 1.6% | Jul 17, 2017 | Apache OpenMeetings 1.0.0 uses not very strong cryptographic storage, captcha is not used in registration and forget pas... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now