2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-9022 | HIGH | 7.5 | 2.0% | Jun 8, 2017 | The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which ... |
| CVE-2017-8108 | — | — | 0.4% | Jun 8, 2017 | Unspecified tests in Lynis before 2.5.0 allow local users to write to arbitrary files or possibly gain privileges via a ... |
| CVE-2017-5878 | CRITICAL | 9.8 | 2.7% | Jun 8, 2017 | The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserializatio... |
| CVE-2017-9520 | — | — | 1.1% | Jun 8, 2017 | The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service ... |
| CVE-2017-9519 | — | — | 0.5% | Jun 8, 2017 | atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account. |
| CVE-2017-9518 | — | — | 0.5% | Jun 8, 2017 | atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails. |
| CVE-2017-9517 | — | — | 0.5% | Jun 8, 2017 | atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV. |
| CVE-2017-9516 | — | — | 2.3% | Jun 8, 2017 | Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. |
| CVE-2017-6648 | — | — | 3.6% | Jun 8, 2017 | A vulnerability in the Session Initiation Protocol (SIP) of the Cisco TelePresence Codec (TC) and Collaboration Endpoint... |
| CVE-2017-6640 | — | — | 10.7% | Jun 8, 2017 | A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attack... |
| CVE-2017-6639 | — | — | 35.4% | Jun 8, 2017 | A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) ... |
| CVE-2017-6638 | — | — | 0.4% | Jun 8, 2017 | A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an auth... |
| CVE-2017-4913 | — | — | 0.4% | Jun 8, 2017 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain an integer-overflow vulne... |
| CVE-2017-4912 | — | — | 0.4% | Jun 8, 2017 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds re... |
| CVE-2017-4911 | — | — | 0.4% | Jun 8, 2017 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds wr... |
| CVE-2017-4910 | — | — | 0.4% | Jun 8, 2017 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds re... |
| CVE-2017-4909 | — | — | 0.4% | Jun 8, 2017 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vu... |
| CVE-2017-4908 | — | — | 0.4% | Jun 8, 2017 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-over... |
| CVE-2017-4907 | — | — | 3.8% | Jun 8, 2017 | VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.... |
| CVE-2017-4901 | — | — | 19.9% | Jun 8, 2017 | The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 ha... |
| CVE-2017-7180 | HIGH | 7.3 | 1.1% | Jun 8, 2017 | Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its ... |
| CVE-2017-9355 | — | — | 26.9% | Jun 7, 2017 | XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to... |
| CVE-2017-7966 | — | — | 2.4% | Jun 7, 2017 | A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote ... |
| CVE-2017-7965 | HIGH | 7.3 | 0.4% | Jun 7, 2017 | A buffer overflow vulnerability exists in Programming Software executable AlTracePrint.exe, in Schneider Electric's SoMa... |
| CVE-2017-4905 | MEDIUM | 5.5 | 1.2% | Jun 7, 2017 | VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now