2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-7679In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_mime can read one byte past the end of a buffer when se...
CVE-2017-7668HIGH7.5The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which al...
CVE-2017-3169In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, mod_ssl may dereference a NULL pointer when third-party mod...
CVE-2017-3167CRITICAL9.8In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules ou...
CVE-2017-3745In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user...
CVE-2017-3744In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in th...
CVE-2017-3743If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsC...
CVE-2017-3216WiMAX routers based on the MediaTek SDK (libmtk) that use a custom httpd plugin are vulnerable to an authentication bypa...
CVE-2017-3215The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one year. This bearer token, i...
CVE-2017-3214HIGH7.5The Milwaukee ONE-KEY Android mobile application stores the master token in plaintext in the apk binary.
CVE-2017-9763The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 ...
CVE-2017-9762The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use...
CVE-2017-9761The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-bas...
CVE-2017-1000379HIGH7.8The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where ...
CVE-2017-1000378The NetBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N ...
CVE-2017-1000377An issue was discovered in the size of the default stack guard page on PAX Linux (originally from GRSecurity but shipped...
CVE-2017-1000376HIGH7libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting th...
CVE-2017-1000375NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attacke...
CVE-2017-1000374A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitra...
CVE-2017-1000373The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N...
CVE-2017-1000372A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitr...
CVE-2017-1000371HIGH7.8The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1...
CVE-2017-1000370HIGH7.8The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit...
CVE-2017-1000369MEDIUM4Exim supports the use of multiple "-p" command line arguments which are malloc()'ed and never free()'ed, used in conjunc...
CVE-2017-1000366glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causin...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now