2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-3876 | — | — | 2.5% | May 16, 2017 | A vulnerability in the Event Management Service daemon (emsd) of Cisco IOS XR routers could allow an unauthenticated, re... |
| CVE-2017-3873 | — | — | 0.7% | May 16, 2017 | A vulnerability in the Plug-and-Play (PnP) subsystem of the Cisco Aironet 1800, 2800, and 3800 Series Access Points runn... |
| CVE-2017-3825 | — | — | 3.0% | May 16, 2017 | A vulnerability in the ICMP ingress packet processing of Cisco TelePresence Collaboration Endpoint (CE) Software could a... |
| CVE-2017-6887 | — | — | 1.6% | May 16, 2017 | A boundary error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can... |
| CVE-2017-6886 | — | — | 3.4% | May 16, 2017 | An error within the "parse_tiff_ifd()" function (internal/dcraw_common.cpp) in LibRaw versions before 0.18.2 can be expl... |
| CVE-2017-6885 | — | — | 1.2% | May 16, 2017 | An error when handling certain external commands and services related to the FlexNet Inventory Agent and FlexNet Beacon ... |
| CVE-2017-8382 | — | — | 2.6% | May 16, 2017 | admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc... |
| CVE-2017-7953 | — | — | 1.0% | May 16, 2017 | INFOR EAM V11.0 Build 201410 has XSS via comment fields. |
| CVE-2017-7952 | — | — | 1.4% | May 16, 2017 | INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter. |
| CVE-2017-8943 | MEDIUM | 5.9 | 0.6% | May 15, 2017 | The PUMA PUMATRAC app 3.0.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle ... |
| CVE-2017-8942 | — | — | 0.5% | May 15, 2017 | The YottaMark ShopWell - Healthy Diet & Grocery Food Scanner app 5.3.7 through 5.4.2 for iOS does not verify X.509 certi... |
| CVE-2017-8941 | — | — | 0.6% | May 15, 2017 | The Interval International app 3.3 through 3.5.1 for iOS does not verify X.509 certificates from SSL servers, which allo... |
| CVE-2017-8940 | — | — | 0.5% | May 15, 2017 | The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL serve... |
| CVE-2017-8939 | MEDIUM | 5.9 | 0.6% | May 15, 2017 | The Warner Bros. ellentube app 3.1.1 through 3.1.3 for iOS does not verify X.509 certificates from SSL servers, which al... |
| CVE-2017-8938 | MEDIUM | 5.9 | 0.7% | May 15, 2017 | The Radio Javan app 9.3.4 through 9.6.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in... |
| CVE-2017-8937 | — | — | 0.5% | May 15, 2017 | The Life Before Us Yo app 2.5.8 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-mid... |
| CVE-2017-8936 | MEDIUM | 5.9 | 0.6% | May 15, 2017 | The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 c... |
| CVE-2017-8935 | MEDIUM | 5.9 | 0.6% | May 15, 2017 | The Quest Information Systems Indiana Voters app 1.1.24 for iOS does not verify X.509 certificates from SSL servers, whi... |
| CVE-2017-8927 | HIGH | 7.8 | 3.0% | May 15, 2017 | Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified ... |
| CVE-2017-8926 | — | — | 3.1% | May 15, 2017 | Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspeci... |
| CVE-2017-7499 | — | — | — | May 15, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-8933. Reason: This candidate is a reservation ... |
| CVE-2017-7498 | — | — | — | May 15, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-8934. Reason: This candidate is a reservation ... |
| CVE-2017-7495 | — | — | 0.4% | May 15, 2017 | fs/ext4/inode.c in the Linux kernel before 4.6.2, when ext4 data=ordered mode is used, mishandles a needs-flushing-befor... |
| CVE-2017-7479 | — | — | 1.9% | May 15, 2017 | OpenVPN versions before 2.3.15 and before 2.4.2 are vulnerable to reachable assertion when packet-ID counter rolls over ... |
| CVE-2017-7478 | — | — | 13.9% | May 15, 2017 | OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now