2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-18307MEDIUM5.5Information disclosure possible while audio playback.
CVE-2017-18306MEDIUM5.5Information disclosure due to uninitialized variable.
CVE-2017-18153HIGH7A race condition exists in a driver potentially leading to a use-after-free condition.
CVE-2017-17772CRITICAL9.8In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation.
CVE-2017-15832HIGH7.8Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW
CVE-2017-11076CRITICAL9.8On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into t...
CVE-2017-9711HIGH7.8Certain unprivileged processes are able to perform IOCTL calls.
CVE-2017-13315HIGH7.8In writeToParcel and createFromParcel of DcParamObject.java, there is a permission bypass due to a write size mismatch. ...
CVE-2017-13314HIGH7.8In setAllowOnlyVpnForUids of NetworkManagementService.java, there is a possible security settings bypass due to a missin...
CVE-2017-13313MEDIUM6.5In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resou...
CVE-2017-13312HIGH7.8In createFromParcel of MediaCas.java, there is a possible parcel read/write mismatch due to improper input validation. T...
CVE-2017-13311MEDIUM6.7In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions...
CVE-2017-13310HIGH7.8In createFromParcel of ViewPager.java, there is a possible read/write serialization issue leading to a permissions bypas...
CVE-2017-13309MEDIUM5.5In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This cou...
CVE-2017-13227MEDIUM5.5In the autofill service, the package name that is provided by the app process is trusted inappropriately.  This could le...
CVE-2017-20195MEDIUM5.5A vulnerability was found in LUNAD3v AreaLoad up to 1a1103182ed63a06dde63d1712f3262eda19c3ec. It has been rated as criti...
CVE-2017-20194MEDIUM5.3The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and includi...
CVE-2017-20193MEDIUM6.1The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions u...
CVE-2017-20192MEDIUM6.1The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters su...
CVE-2017-3772MEDIUM5.5A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a ...
CVE-2017-3769Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2017-3766Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2017-3755Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2017-20191LOW3.5A vulnerability was found in Zimbra zm-admin-ajax up to 8.8.1. It has been classified as problematic. This affects the f...
CVE-2017-20190Some Microsoft technologies as used in Windows 8 through 11 allow a temporary client-side performance degradation during...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now