2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8314 | — | — | 2.5% | May 23, 2017 | Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via... |
| CVE-2017-8313 | — | — | 1.5% | May 23, 2017 | Heap out-of-bound read in ParseJSS in VideoLAN VLC before 2.2.5 due to missing check of string termination allows attack... |
| CVE-2017-8312 | — | — | 1.4% | May 23, 2017 | Heap out-of-bound read in ParseJSS in VideoLAN VLC due to missing check of string length allows attackers to read heap u... |
| CVE-2017-8311 | — | — | 8.8% | May 23, 2017 | Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu... |
| CVE-2017-8310 | — | — | 1.3% | May 23, 2017 | Heap out-of-bound read in CreateHtmlSubtitle in VideoLAN VLC 2.2.x due to missing check of string termination allows att... |
| CVE-2017-0374 | — | — | 0.4% | May 23, 2017 | lib/Config/Model.pm in Config-Model (aka libconfig-model-perl) before 2.102 allows local users to gain privileges via a ... |
| CVE-2017-0373 | — | — | 1.8% | May 23, 2017 | The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) bef... |
| CVE-2017-9214 | CRITICAL | 9.8 | 2.9% | May 23, 2017 | In Open vSwitch (OvS) 2.7.0, while parsing an OFPT_QUEUE_GET_CONFIG_REPLY type OFP 1.0 message, there is a buffer over-r... |
| CVE-2017-3128 | — | — | 0.7% | May 23, 2017 | A stored XSS (Cross-Site-Scripting) vulnerability in Fortinet FortiOS allows attackers to execute unauthorized code or c... |
| CVE-2017-2797 | HIGH | 8.3 | 0.9% | May 23, 2017 | An exploitable heap overflow vulnerability exists in the ParseEnvironment functionality of AntennaHouse DMC HTMLFilter a... |
| CVE-2017-2794 | HIGH | 8.3 | 1.3% | May 23, 2017 | An exploitable stack-based buffer overflow vulnerability exists in the DHFSummary functionality of AntennaHouse DMC HTML... |
| CVE-2017-2793 | HIGH | 8.3 | 1.4% | May 23, 2017 | An exploitable heap corruption vulnerability exists in the UnCompressUnicode functionality of Antenna House DMC HTMLFilt... |
| CVE-2017-2783 | HIGH | 8.3 | 1.3% | May 23, 2017 | An exploitable heap corruption vulnerability exists in the FillRowFormat functionality of Antenna House DMC HTMLFilter t... |
| CVE-2017-6131 | — | — | 1.1% | May 23, 2017 | In some circumstances, an F5 BIG-IP version 12.0.0 to 12.1.2 and 13.0.0 Azure cloud instance may contain a default admin... |
| CVE-2017-9212 | — | — | 1.1% | May 23, 2017 | The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string ... |
| CVE-2017-9211 | — | — | 0.4% | May 23, 2017 | The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey functio... |
| CVE-2017-5966 | — | — | 1.6% | May 23, 2017 | Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to read arbitrary files via an absolute path trav... |
| CVE-2017-5965 | — | — | 1.0% | May 23, 2017 | The package manager in Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to execute arbitrary ASP c... |
| CVE-2017-9210 | — | — | 1.5% | May 23, 2017 | libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) ... |
| CVE-2017-9209 | — | — | 1.4% | May 23, 2017 | libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) ... |
| CVE-2017-9208 | — | — | 1.3% | May 23, 2017 | libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) ... |
| CVE-2017-9207 | — | — | 1.6% | May 23, 2017 | The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers ... |
| CVE-2017-9206 | — | — | 1.6% | May 23, 2017 | The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers ... |
| CVE-2017-9205 | — | — | 1.6% | May 23, 2017 | The iw_get_ui16be function in imagew-util.c:422:24 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers ... |
| CVE-2017-9204 | — | — | 1.6% | May 23, 2017 | The iw_get_ui16le function in imagew-util.c:405:23 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now