2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-10686 | — | — | 2.9% | Jun 29, 2017 | In Netwide Assembler (NASM) 2.14rc0, there are multiple heap use after free vulnerabilities in the tool nasm. The relate... |
| CVE-2017-10685 | CRITICAL | 9.8 | 4.3% | Jun 29, 2017 | In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote ... |
| CVE-2017-10684 | CRITICAL | 9.8 | 4.9% | Jun 29, 2017 | In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote ... |
| CVE-2017-10683 | HIGH | 7.5 | 1.2% | Jun 29, 2017 | In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted in... |
| CVE-2017-10682 | — | — | 8.2% | Jun 29, 2017 | SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitra... |
| CVE-2017-10681 | — | — | 1.2% | Jun 29, 2017 | Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentica... |
| CVE-2017-10680 | — | — | 1.2% | Jun 29, 2017 | Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentica... |
| CVE-2017-10679 | — | — | 2.5% | Jun 29, 2017 | Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink b... |
| CVE-2017-10678 | — | — | 1.2% | Jun 29, 2017 | Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentica... |
| CVE-2017-4997 | CRITICAL | 9.8 | 4.5% | Jun 29, 2017 | EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability ... |
| CVE-2017-2851 | HIGH | 7.2 | 1.9% | Jun 29, 2017 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted ... |
| CVE-2017-2850 | HIGH | 8.8 | 2.2% | Jun 29, 2017 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted ... |
| CVE-2017-2849 | HIGH | 8.8 | 4.8% | Jun 29, 2017 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted ... |
| CVE-2017-2848 | HIGH | 8.8 | 4.5% | Jun 29, 2017 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted ... |
| CVE-2017-2847 | HIGH | 8.8 | 4.5% | Jun 29, 2017 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted ... |
| CVE-2017-2846 | HIGH | 8.8 | 4.5% | Jun 29, 2017 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted ... |
| CVE-2017-2845 | HIGH | 8.8 | 7.2% | Jun 29, 2017 | An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Ca... |
| CVE-2017-2844 | HIGH | 8.8 | 3.4% | Jun 29, 2017 | In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted ... |
| CVE-2017-3750 | — | — | 0.1% | Jun 29, 2017 | On Lenovo VIBE mobile phones, the Lenovo Security Android application allows private data to be backed up and restored v... |
| CVE-2017-3749 | — | — | 0.1% | Jun 29, 2017 | On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via A... |
| CVE-2017-3748 | — | — | 0.2% | Jun 29, 2017 | On Lenovo VIBE mobile phones, improper access controls on the nac_server component can be abused in conjunction with CVE... |
| CVE-2017-3747 | — | — | 0.3% | Jun 29, 2017 | Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for not... |
| CVE-2017-5529 | MEDIUM | 4.1 | 1.3% | Jun 29, 2017 | JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theore... |
| CVE-2017-5528 | HIGH | 8.8 | 0.6% | Jun 29, 2017 | Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site ... |
| CVE-2017-8613 | — | — | 3.6% | Jun 29, 2017 | Azure AD Connect Password writeback, if misconfigured during enablement, allows an attacker to reset passwords and gain ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now