2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1217 | — | — | 1.1% | Jul 5, 2017 | IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2017-10929 | — | — | 1.9% | Jul 5, 2017 | The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service... |
| CVE-2017-10928 | — | — | 3.6% | Jul 5, 2017 | In ImageMagick 7.0.6-0, a heap-based buffer over-read in the GetNextToken function in token.c allows remote attackers to... |
| CVE-2017-10923 | — | — | 1.8% | Jul 5, 2017 | Xen through 4.8.x does not validate a vCPU array index upon the sending of an SGI, which allows guest OS users to cause ... |
| CVE-2017-10922 | — | — | 2.0% | Jul 5, 2017 | The grant-table feature in Xen through 4.8.x mishandles MMIO region grant references, which allows guest OS users to cau... |
| CVE-2017-10921 | — | — | 2.5% | Jul 5, 2017 | The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_h... |
| CVE-2017-10920 | — | — | 2.5% | Jul 5, 2017 | The grant-table feature in Xen through 4.8.x mishandles a GNTMAP_device_map and GNTMAP_host_map mapping, when followed b... |
| CVE-2017-10919 | — | — | 1.9% | Jul 5, 2017 | Xen through 4.8.x mishandles virtual interrupt injection, which allows guest OS users to cause a denial of service (hype... |
| CVE-2017-10918 | — | — | 3.7% | Jul 5, 2017 | Xen through 4.8.x does not validate memory allocations during certain P2M operations, which allows guest OS users to obt... |
| CVE-2017-10917 | — | — | 2.6% | Jul 5, 2017 | Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause... |
| CVE-2017-10916 | — | — | 1.3% | Jul 5, 2017 | The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (... |
| CVE-2017-10915 | — | — | 1.7% | Jul 5, 2017 | The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, ... |
| CVE-2017-10914 | — | — | 1.6% | Jul 5, 2017 | The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users ... |
| CVE-2017-10913 | — | — | 2.8% | Jul 5, 2017 | The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap cal... |
| CVE-2017-10912 | — | — | 2.7% | Jul 5, 2017 | Xen through 4.8.x mishandles page transfer, which allows guest OS users to obtain privileged host OS access, aka XSA-217... |
| CVE-2017-10911 | — | — | 0.4% | Jul 5, 2017 | The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS user... |
| CVE-2017-10810 | HIGH | 7.5 | 3.8% | Jul 4, 2017 | Memory leak in the virtio_gpu_object_create function in drivers/gpu/drm/virtio/virtgpu_object.c in the Linux kernel thro... |
| CVE-2017-7276 | — | — | 0.6% | Jul 4, 2017 | There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019. |
| CVE-2017-10805 | — | — | 1.0% | Jul 4, 2017 | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on ... |
| CVE-2017-10804 | — | — | 3.4% | Jul 4, 2017 | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass ... |
| CVE-2017-10803 | — | — | 3.6% | Jul 4, 2017 | In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymi... |
| CVE-2017-10807 | — | — | 2.9% | Jul 4, 2017 | JabberD 2.x (aka jabberd2) before 2.6.1 allows anyone to authenticate using SASL ANONYMOUS, even when the sasl.anonymous... |
| CVE-2017-9313 | — | — | 1.4% | Jul 4, 2017 | Multiple Cross-site scripting (XSS) vulnerabilities in Webmin before 1.850 allow remote attackers to inject arbitrary we... |
| CVE-2017-7317 | — | — | 2.2% | Jul 4, 2017 | An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup f... |
| CVE-2017-7316 | — | — | 0.8% | Jul 4, 2017 | An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is XSS on the 404 page. |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now