2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-6890A boundary error within the "foveon_load_camf()" function (dcraw_foveon.c) when initializing a huffman table in LibRaw-d...
CVE-2017-6889An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before ...
CVE-2017-0252A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling...
CVE-2017-0223A remote code execution vulnerability exists in Microsoft Chakra Core in the way JavaScript engines render when handling...
CVE-2017-8934PCManFM 1.2.5 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (application un...
CVE-2017-8933Libmenu-cache 1.0.2 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (menu una...
CVE-2017-7491In Moodle 2.x and 3.x, a CSRF attack is possible that allows attackers to change the "number of courses displayed in the...
CVE-2017-7490In Moodle 2.x and 3.x, searching of arbitrary blogs is possible because a capability check is missing.
CVE-2017-7489In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link...
CVE-2017-5655In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Se...
CVE-2017-7213Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected activ...
CVE-2017-8930Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hi...
CVE-2017-8929The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (...
CVE-2017-8928HIGH8.8mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.
CVE-2017-7487HIGH7.8The ipxitf_ioctl function in net/ipx/af_ipx.c in the Linux kernel through 4.11.1 mishandles reference counts, which allo...
CVE-2017-8925The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause ...
CVE-2017-8924The edge_bulk_in_callback function in drivers/usb/serial/io_ti.c in the Linux kernel before 4.10.4 allows local users to...
CVE-2017-5654In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may be able to gain unauthor...
CVE-2017-8923CRITICAL9.8The zend_string_extend function in Zend/zend_string.h in PHP through 7.1.5 does not prevent changes to string objects th...
CVE-2017-8246HIGH7.8In function msm_pcm_playback_close() in all Android releases from CAF using the Linux kernel, prtd is assigned substream...
CVE-2017-8245HIGH7.8In all Android releases from CAF using the Linux kernel, while processing a voice SVC request which is nonstandard by sp...
CVE-2017-8244HIGH7In core_info_read and inst_info_read in all Android releases from CAF using the Linux kernel, variable "dbg_buf", "dbg_b...
CVE-2017-8921In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not...
CVE-2017-7486PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server...
CVE-2017-7485In PostgreSQL 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3, it was found that th...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now