2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-9036 | HIGH | 7.8 | 0.5% | May 26, 2017 | Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestrict... |
| CVE-2017-9035 | HIGH | 7.4 | 3.6% | May 26, 2017 | Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveragi... |
| CVE-2017-9034 | CRITICAL | 9.8 | 6.0% | May 26, 2017 | Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently exe... |
| CVE-2017-9033 | HIGH | 8.8 | 2.3% | May 26, 2017 | Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote ... |
| CVE-2017-9032 | MEDIUM | 6.1 | 2.5% | May 26, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allow remo... |
| CVE-2017-7439 | — | — | 1.9% | May 26, 2017 | NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive inform... |
| CVE-2017-7236 | — | — | 1.8% | May 26, 2017 | SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers ... |
| CVE-2017-5868 | — | — | 4.6% | May 26, 2017 | CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbit... |
| CVE-2017-9230 | HIGH | 7.5 | 3.3% | May 24, 2017 | The Bitcoin Proof-of-Work algorithm does not consider a certain attack methodology related to 80-byte block headers with... |
| CVE-2017-9229 | HIGH | 7.5 | 5.1% | May 24, 2017 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7... |
| CVE-2017-9228 | CRITICAL | 9.8 | 6.3% | May 24, 2017 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7... |
| CVE-2017-9227 | CRITICAL | 9.8 | 6.3% | May 24, 2017 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7... |
| CVE-2017-9226 | CRITICAL | 9.8 | 7.5% | May 24, 2017 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7... |
| CVE-2017-9225 | — | — | 3.1% | May 24, 2017 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7... |
| CVE-2017-9224 | CRITICAL | 9.8 | 6.5% | May 24, 2017 | An issue was discovered in Oniguruma 6.2.0, as used in Oniguruma-mod in Ruby through 2.4.1 and mbstring in PHP through 7... |
| CVE-2017-2824 | — | — | 26.1% | May 24, 2017 | An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specia... |
| CVE-2017-2823 | HIGH | 7.8 | 9.4% | May 24, 2017 | A use-after-free vulnerability exists in the .ISO parsing functionality of PowerISO 6.8. A specially crafted .ISO file c... |
| CVE-2017-2819 | HIGH | 8.8 | 1.7% | May 24, 2017 | An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom T... |
| CVE-2017-2817 | HIGH | 8.8 | 1.7% | May 24, 2017 | A stack buffer overflow vulnerability exists in the ISO parsing functionality of Power Software Ltd PowerISO 6.8. A spec... |
| CVE-2017-2801 | MEDIUM | 6.5 | 1.3% | May 24, 2017 | A programming error exists in a way Randombit Botan cryptographic library version 2.0.1 implements x500 string compariso... |
| CVE-2017-2800 | CRITICAL | 9.8 | 8.5% | May 24, 2017 | A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting... |
| CVE-2017-2799 | HIGH | 8.3 | 1.3% | May 24, 2017 | An exploitable heap corruption vulnerability exists in the AddSst functionality of Antenna House DMC HTMLFilter as used ... |
| CVE-2017-2798 | HIGH | 8.3 | 1.3% | May 24, 2017 | An exploitable heap corruption vulnerability exists in the GetIndexArray functionality of Antenna House DMC HTMLFilter a... |
| CVE-2017-9217 | HIGH | 7.5 | 15.4% | May 24, 2017 | systemd-resolved through 233 allows remote attackers to cause a denial of service (daemon crash) via a crafted DNS respo... |
| CVE-2017-9216 | MEDIUM | 6.5 | 3.5% | May 24, 2017 | libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_hu... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now