2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-0229 | — | — | 10.7% | May 12, 2017 | A remote code execution vulnerability exists in Microsoft Edge in the way JavaScript engines render when handling object... |
| CVE-2017-0228 | — | — | 17.0% | May 12, 2017 | A remote code execution vulnerability exists in Microsoft browsers in the way JavaScript engines render when handling ob... |
| CVE-2017-0227 | — | — | 13.8% | May 12, 2017 | A remote code execution vulnerability exists in Microsoft Edge in the way affected Microsoft scripting engines render wh... |
| CVE-2017-0226 | — | — | 9.8% | May 12, 2017 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet... |
| CVE-2017-0224 | — | — | 11.4% | May 12, 2017 | A remote code execution vulnerability exists in the way JavaScript engines render when handling objects in memory in Mic... |
| CVE-2017-0222 | HIGH | 8.8 | 29.6% | May 12, 2017 | A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet... |
| CVE-2017-0221 | — | — | 4.8% | May 12, 2017 | A vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption ... |
| CVE-2017-0220 | — | — | 7.5% | May 12, 2017 | The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticat... |
| CVE-2017-0214 | — | — | 3.5% | May 12, 2017 | Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2... |
| CVE-2017-0213 | HIGH | 7.3 | 84.1% | May 12, 2017 | Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser... |
| CVE-2017-0212 | — | — | 1.1% | May 12, 2017 | Windows Hyper-V allows an elevation of privilege vulnerability when Microsoft Windows 10 Gold, 1511, 1607, and 1703, and... |
| CVE-2017-0190 | — | — | 43.5% | May 12, 2017 | The GDI component in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold ... |
| CVE-2017-0175 | — | — | 7.0% | May 12, 2017 | The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sen... |
| CVE-2017-0171 | — | — | 4.1% | May 12, 2017 | Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows S... |
| CVE-2017-0077 | — | — | 1.5% | May 12, 2017 | The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and ... |
| CVE-2017-0064 | — | — | 5.2% | May 12, 2017 | A security feature bypass vulnerability exists in Internet Explorer that allows for bypassing Mixed Content warnings, ak... |
| CVE-2017-8912 | HIGH | 7.2 | 3.1% | May 12, 2017 | CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code para... |
| CVE-2017-8911 | — | — | 1.9% | May 12, 2017 | An integer underflow has been identified in the unicode_to_utf8() function in tnef 1.4.14. This might lead to invalid wr... |
| CVE-2017-8908 | — | — | 1.1% | May 12, 2017 | The mark_line_tr function in gxscanc.c in Artifex Ghostscript 9.21 allows remote attackers to cause a denial of service ... |
| CVE-2017-8900 | — | — | 0.4% | May 12, 2017 | LightDM through 1.22.0, when systemd is used in Ubuntu 16.10 and 17.x, allows physically proximate attackers to bypass i... |
| CVE-2017-8360 | — | — | 0.5% | May 12, 2017 | Conexant Systems mictray64 task, as used on HP Elite, EliteBook, ProBook, and ZBook systems, leaks sensitive data (keyst... |
| CVE-2017-8906 | MEDIUM | 5.5 | 0.8% | May 11, 2017 | An integer underflow vulnerability exists in pixel-a.asm, the x86 assembly code for planeClipAndMax() in MulticoreWare x... |
| CVE-2017-8905 | — | — | 0.4% | May 11, 2017 | Xen through 4.6.x on 64-bit platforms mishandles a failsafe callback, which might allow PV guest OS users to execute arb... |
| CVE-2017-8904 | — | — | 0.4% | May 11, 2017 | Xen through 4.8.x mishandles the "contains segment descriptors" property during GNTTABOP_transfer (aka guest transfer) o... |
| CVE-2017-8903 | — | — | 0.5% | May 11, 2017 | Xen through 4.8.x on 64-bit platforms mishandles page tables after an IRET hypercall, which might allow PV guest OS user... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now