2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5943 | — | — | 0.8% | Jul 3, 2017 | Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain se... |
| CVE-2017-5361 | — | — | 1.4% | Jul 3, 2017 | Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time compari... |
| CVE-2017-10798 | — | — | 0.6% | Jul 3, 2017 | In ObjectPlanet Opinio before 7.6.4, there is XSS. |
| CVE-2017-10800 | — | — | 1.2% | Jul 3, 2017 | When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMAT... |
| CVE-2017-10799 | — | — | 1.3% | Jul 3, 2017 | When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of s... |
| CVE-2017-10796 | MEDIUM | 6.5 | 0.9% | Jul 2, 2017 | On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authenticatio... |
| CVE-2017-10794 | — | — | 1.5% | Jul 2, 2017 | When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/... |
| CVE-2017-8894 | — | — | 1.6% | Jul 2, 2017 | AeroAdmin 4.1 uses an insecure protocol (HTTP) to perform software updates. An attacker can hijack an update via man-in-... |
| CVE-2017-8893 | — | — | 1.1% | Jul 2, 2017 | AeroAdmin 4.1 uses a function to copy data between two pointers where the size of the data copied is taken directly from... |
| CVE-2017-8797 | HIGH | 7.5 | 8.7% | Jul 2, 2017 | The NFSv4 server in the Linux kernel before 4.11.3 does not properly validate the layout type when processing the NFSv4 ... |
| CVE-2017-0377 | — | — | 2.4% | Jul 2, 2017 | Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family... |
| CVE-2017-10795 | — | — | 1.1% | Jul 2, 2017 | Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or ... |
| CVE-2017-10706 | — | — | 0.3% | Jul 2, 2017 | When Antiy Antivirus Engine before 5.0.0.05171547 scans a special ZIP archive, it crashes with a stack-based buffer over... |
| CVE-2017-10792 | — | — | 1.6% | Jul 2, 2017 | There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For ex... |
| CVE-2017-10791 | — | — | 1.6% | Jul 2, 2017 | There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a c... |
| CVE-2017-10790 | — | — | 5.0% | Jul 2, 2017 | The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when readin... |
| CVE-2017-10789 | — | — | 2.2% | Jul 1, 2017 | The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this... |
| CVE-2017-10788 | — | — | 4.6% | Jul 1, 2017 | The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and ap... |
| CVE-2017-2298 | MEDIUM | 6.5 | 1.5% | Jun 30, 2017 | The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path wher... |
| CVE-2017-2292 | — | — | 2.2% | Jun 30, 2017 | Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential ... |
| CVE-2017-8443 | — | — | 1.1% | Jun 30, 2017 | In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redi... |
| CVE-2017-10709 | — | — | 0.3% | Jun 30, 2017 | The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-P... |
| CVE-2017-10699 | — | — | 4.5% | Jun 30, 2017 | avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write du... |
| CVE-2017-10674 | — | — | 0.3% | Jun 30, 2017 | Antiy Antivirus Engine 5.0.0.06281654 allows local users to cause a denial of service (BSOD) via a long third argument i... |
| CVE-2017-10670 | — | — | 1.4% | Jun 30, 2017 | An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now