2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-5943Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain se...
CVE-2017-5361Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 does not use a constant-time compari...
CVE-2017-10798In ObjectPlanet Opinio before 7.6.4, there is XSS.
CVE-2017-10800When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMAT...
CVE-2017-10799When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of s...
CVE-2017-10796MEDIUM6.5On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authenticatio...
CVE-2017-10794When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/...
CVE-2017-8894AeroAdmin 4.1 uses an insecure protocol (HTTP) to perform software updates. An attacker can hijack an update via man-in-...
CVE-2017-8893AeroAdmin 4.1 uses a function to copy data between two pointers where the size of the data copied is taken directly from...
CVE-2017-8797HIGH7.5The NFSv4 server in the Linux kernel before 4.11.3 does not properly validate the layout type when processing the NFSv4 ...
CVE-2017-0377Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family...
CVE-2017-10795Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or ...
CVE-2017-10706When Antiy Antivirus Engine before 5.0.0.05171547 scans a special ZIP archive, it crashes with a stack-based buffer over...
CVE-2017-10792There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For ex...
CVE-2017-10791There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a c...
CVE-2017-10790The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when readin...
CVE-2017-10789The DBD::mysql module through 4.043 for Perl uses the mysql_ssl=1 setting to mean that SSL is optional (even though this...
CVE-2017-10788The DBD::mysql module through 4.043 for Perl allows remote attackers to cause a denial of service (use-after-free and ap...
CVE-2017-2298MEDIUM6.5The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path wher...
CVE-2017-2292Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential ...
CVE-2017-8443In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redi...
CVE-2017-10709The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-P...
CVE-2017-10699avcodec 2.2.x, as used in VideoLAN VLC media player 2.2.7-x before 2017-06-29, allows out-of-bounds heap memory write du...
CVE-2017-10674Antiy Antivirus Engine 5.0.0.06281654 allows local users to cause a denial of service (BSOD) via a long third argument i...
CVE-2017-10670An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now