2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-1000380 | — | — | 0.7% | Jun 17, 2017 | sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resu... |
| CVE-2017-9736 | — | — | 3.2% | Jun 17, 2017 | SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a rem... |
| CVE-2017-9503 | MEDIUM | 5.5 | 0.4% | Jun 16, 2017 | QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest O... |
| CVE-2017-9375 | MEDIUM | 5.5 | 0.4% | Jun 16, 2017 | QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users ... |
| CVE-2017-9374 | MEDIUM | 5.5 | 0.4% | Jun 16, 2017 | Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged u... |
| CVE-2017-9373 | MEDIUM | 5.5 | 0.4% | Jun 16, 2017 | Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged u... |
| CVE-2017-9231 | — | — | 1.8% | Jun 16, 2017 | XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obta... |
| CVE-2017-9735 | HIGH | 7.5 | 5.8% | Jun 16, 2017 | Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attack... |
| CVE-2017-8452 | — | — | 1.4% | Jun 16, 2017 | Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certa... |
| CVE-2017-8451 | — | — | 0.9% | Jun 16, 2017 | With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would ena... |
| CVE-2017-8450 | — | — | 0.9% | Jun 16, 2017 | X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users wi... |
| CVE-2017-8449 | — | — | 0.8% | Jun 16, 2017 | X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules... |
| CVE-2017-7507 | — | — | 3.4% | Jun 16, 2017 | GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS exten... |
| CVE-2017-6899 | — | — | 0.3% | Jun 16, 2017 | The msm_bus_dbg_update_request_write function in drivers/platform/msm/msm_bus/msm_bus_dbg.c in android_kernel_huawei_msm... |
| CVE-2017-9731 | — | — | 1.1% | Jun 16, 2017 | In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers ... |
| CVE-2017-9729 | — | — | 1.1% | Jun 16, 2017 | In uClibc 0.9.33.2, there is stack exhaustion (uncontrolled recursion) in the check_dst_limits_calc_pos_1 function in mi... |
| CVE-2017-9728 | — | — | 1.2% | Jun 16, 2017 | In uClibc 0.9.33.2, there is an out-of-bounds read in the get_subexp function in misc/regex/regexec.c when processing a ... |
| CVE-2017-9602 | CRITICAL | 9.8 | 4.3% | Jun 16, 2017 | KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-man... |
| CVE-2017-7884 | — | — | 0.4% | Jun 16, 2017 | In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticate... |
| CVE-2017-9601 | — | — | 0.5% | Jun 16, 2017 | The "FNB Kemp Mobile Banking" by First National Bank of Kemp app 3.0.2 -- aka fnb-kemp-mobile-banking/id571448725 for iO... |
| CVE-2017-9600 | — | — | 0.5% | Jun 16, 2017 | The "Peoples Bank Tulsa" by Peoples Bank - OK app 3.0.2 -- aka peoples-bank-tulsa/id1074279285 for iOS does not verify X... |
| CVE-2017-9599 | — | — | 0.5% | Jun 16, 2017 | The "Fountain Trust Mobile Banking" by FOUNTAIN TRUST COMPANY app before 3.2.0 -- aka fountain-trust-mobile-banking/id89... |
| CVE-2017-9598 | — | — | 0.5% | Jun 16, 2017 | The "Morton Credit Union Mobile Banking" by Morton Credit Union app 3.0.1 -- aka morton-credit-union-mobile-banking/id11... |
| CVE-2017-9597 | — | — | 0.5% | Jun 16, 2017 | The "Blue Ridge Bank and Trust Co. Mobile Banking" by Blue Ridge Bank and Trust Co. app 3.0.1 -- aka blue-ridge-bank-and... |
| CVE-2017-9596 | — | — | 0.5% | Jun 16, 2017 | The "CFB Mobile Banking" by Citizens First Bank Wisconsin app 3.0.1 -- aka cfb-mobile-banking/id1081102805 for iOS does ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now