2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-1000380sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resu...
CVE-2017-9736SPIP 3.1.x before 3.1.6 and 3.2.x before Beta 3 does not remove shell metacharacters from the host field, allowing a rem...
CVE-2017-9503MEDIUM5.5QEMU (aka Quick Emulator), when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest O...
CVE-2017-9375MEDIUM5.5QEMU (aka Quick Emulator), when built with USB xHCI controller emulator support, allows local guest OS privileged users ...
CVE-2017-9374MEDIUM5.5Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged u...
CVE-2017-9373MEDIUM5.5Memory leak in QEMU (aka Quick Emulator), when built with IDE AHCI Emulation support, allows local guest OS privileged u...
CVE-2017-9231XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obta...
CVE-2017-9735HIGH7.5Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attack...
CVE-2017-8452Kibana versions prior to 5.2.1 configured for SSL client access, file descriptors will fail to be cleaned up after certa...
CVE-2017-8451With X-Pack installed, Kibana versions before 5.3.1 have an open redirect vulnerability on the login page that would ena...
CVE-2017-8450X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users wi...
CVE-2017-8449X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules...
CVE-2017-7507GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS exten...
CVE-2017-6899The msm_bus_dbg_update_request_write function in drivers/platform/msm/msm_bus/msm_bus_dbg.c in android_kernel_huawei_msm...
CVE-2017-9731In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers ...
CVE-2017-9729In uClibc 0.9.33.2, there is stack exhaustion (uncontrolled recursion) in the check_dst_limits_calc_pos_1 function in mi...
CVE-2017-9728In uClibc 0.9.33.2, there is an out-of-bounds read in the get_subexp function in misc/regex/regexec.c when processing a ...
CVE-2017-9602CRITICAL9.8KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-man...
CVE-2017-7884In Adam Kropelin adk0212 APC UPS Daemon through 3.14.14, the default installation of APCUPSD allows a local authenticate...
CVE-2017-9601The "FNB Kemp Mobile Banking" by First National Bank of Kemp app 3.0.2 -- aka fnb-kemp-mobile-banking/id571448725 for iO...
CVE-2017-9600The "Peoples Bank Tulsa" by Peoples Bank - OK app 3.0.2 -- aka peoples-bank-tulsa/id1074279285 for iOS does not verify X...
CVE-2017-9599The "Fountain Trust Mobile Banking" by FOUNTAIN TRUST COMPANY app before 3.2.0 -- aka fountain-trust-mobile-banking/id89...
CVE-2017-9598The "Morton Credit Union Mobile Banking" by Morton Credit Union app 3.0.1 -- aka morton-credit-union-mobile-banking/id11...
CVE-2017-9597The "Blue Ridge Bank and Trust Co. Mobile Banking" by Blue Ridge Bank and Trust Co. app 3.0.1 -- aka blue-ridge-bank-and...
CVE-2017-9596The "CFB Mobile Banking" by Citizens First Bank Wisconsin app 3.0.1 -- aka cfb-mobile-banking/id1081102805 for iOS does ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now