2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-4904 | HIGH | 8.8 | 0.4% | Jun 7, 2017 | The XHCI controller in VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.... |
| CVE-2017-4903 | HIGH | 8.8 | 0.4% | Jun 7, 2017 | VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6.0 U2 without patch ESXi... |
| CVE-2017-4902 | HIGH | 8.8 | 0.5% | Jun 7, 2017 | VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player ... |
| CVE-2017-4900 | — | — | 0.3% | Jun 7, 2017 | VMware Workstation Pro/Player 12.x before 12.5.3 contains a NULL pointer dereference vulnerability that exists in the SV... |
| CVE-2017-4899 | — | — | 0.3% | Jun 7, 2017 | VMware Workstation Pro/Player 12.x before 12.5.3 contains a security vulnerability that exists in the SVGA driver. An at... |
| CVE-2017-4898 | — | — | 0.4% | Jun 7, 2017 | VMware Workstation Pro/Player 12.x before 12.5.3 contains a DLL loading vulnerability that occurs due to the "vmware-vmx... |
| CVE-2017-4917 | — | — | 0.6% | Jun 7, 2017 | VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reve... |
| CVE-2017-4914 | — | — | 8.8% | Jun 7, 2017 | VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of th... |
| CVE-2017-1305 | — | — | 0.7% | Jun 7, 2017 | IBM DOORS Next Generation (DNG/RRC) 6.0.2 and 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows use... |
| CVE-2017-1196 | — | — | 1.7% | Jun 7, 2017 | IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, w... |
| CVE-2017-1178 | — | — | 1.0% | Jun 7, 2017 | IBM Endpoint Manager for Security and Compliance 1.9.70 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2017-1125 | — | — | 0.3% | Jun 7, 2017 | IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expo... |
| CVE-2017-7564 | HIGH | 7.5 | 1.0% | Jun 7, 2017 | In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to ca... |
| CVE-2017-7563 | HIGH | 8.1 | 0.9% | Jun 7, 2017 | In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_E... |
| CVE-2017-9501 | — | — | 1.9% | Jun 7, 2017 | In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function LockSemaphoreInfo, which allows attackers to ... |
| CVE-2017-9500 | — | — | 2.3% | Jun 7, 2017 | In ImageMagick 7.0.5-8 Q16, an assertion failure was found in the function ResetImageProfileIterator, which allows attac... |
| CVE-2017-9499 | — | — | 1.7% | Jun 7, 2017 | In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function SetPixelChannelAttributes, which allows attac... |
| CVE-2017-7314 | — | — | 3.3% | Jun 7, 2017 | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating... |
| CVE-2017-7313 | — | — | 1.3% | Jun 7, 2017 | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible... |
| CVE-2017-7312 | CRITICAL | 9.8 | 3.0% | Jun 7, 2017 | An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add... |
| CVE-2017-9474 | — | — | 0.9% | Jun 7, 2017 | In ytnef 1.9.2, the DecompressRTF function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-bas... |
| CVE-2017-9473 | — | — | 1.2% | Jun 7, 2017 | In ytnef 1.9.2, the TNEFFillMapi function in lib/ytnef.c allows remote attackers to cause a denial of service (memory co... |
| CVE-2017-9472 | — | — | 0.9% | Jun 7, 2017 | In ytnef 1.9.2, the SwapDWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based b... |
| CVE-2017-9471 | — | — | 1.2% | Jun 7, 2017 | In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based bu... |
| CVE-2017-9470 | — | — | 0.9% | Jun 7, 2017 | In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now