2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7472 | — | — | 2.3% | May 11, 2017 | The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumptio... |
| CVE-2017-8851 | — | — | 0.5% | May 11, 2017 | An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA image... |
| CVE-2017-8850 | — | — | 0.4% | May 11, 2017 | An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA imag... |
| CVE-2017-5948 | — | — | 0.8% | May 11, 2017 | An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade att... |
| CVE-2017-8899 | — | — | 1.5% | May 11, 2017 | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has a composite of Stored XSS and Information Disclos... |
| CVE-2017-8898 | — | — | 1.9% | May 11, 2017 | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has stored XSS in the Announcements, allowing privile... |
| CVE-2017-8897 | — | — | 1.2% | May 11, 2017 | Invision Power Services (IPS) Community Suite 4.1.19.2 and earlier has pre-auth reflected XSS in the IPS UTF8 Converter ... |
| CVE-2017-6867 | — | — | 1.9% | May 11, 2017 | A vulnerability was discovered in Siemens SIMATIC WinCC (V7.3 before Upd 11 and V7.4 before SP1), SIMATIC WinCC Runtime ... |
| CVE-2017-6865 | — | — | 0.5% | May 11, 2017 | A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All ... |
| CVE-2017-2681 | MEDIUM | 6.5 | 0.9% | May 11, 2017 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a d... |
| CVE-2017-8798 | — | — | 24.0% | May 11, 2017 | Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of s... |
| CVE-2017-5461 | — | — | 4.7% | May 11, 2017 | Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.... |
| CVE-2017-2680 | MEDIUM | 6.5 | 1.1% | May 11, 2017 | Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a loc... |
| CVE-2017-8895 | — | — | 71.0% | May 10, 2017 | In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a u... |
| CVE-2017-8892 | — | — | 0.9% | May 10, 2017 | Cross-site scripting (XSS) vulnerability in OpenText Tempo Box 10.0.3 allows remote attackers to inject arbitrary web sc... |
| CVE-2017-8852 | — | — | 3.3% | May 10, 2017 | SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file... |
| CVE-2017-8891 | — | — | 0.9% | May 10, 2017 | Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensur... |
| CVE-2017-8890 | HIGH | 7.8 | 1.4% | May 10, 2017 | The inet_csk_clone_lock function in net/ipv4/inet_connection_sock.c in the Linux kernel through 4.10.15 allows attackers... |
| CVE-2017-3894 | — | — | 0.8% | May 10, 2017 | A stored cross site scripting vulnerability in the Management Console of BlackBerry Unified Endpoint Manager version 12.... |
| CVE-2017-6959 | — | — | — | May 10, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-8879 | — | — | 0.4% | May 10, 2017 | Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physica... |
| CVE-2017-7888 | — | — | 1.1% | May 10, 2017 | Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier. |
| CVE-2017-7887 | — | — | 0.9% | May 10, 2017 | Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter. |
| CVE-2017-7886 | — | — | 1.7% | May 10, 2017 | Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter. |
| CVE-2017-7698 | — | — | 1.7% | May 10, 2017 | A Use After Free in the pdf2swf part of swftools 0.9.2 and earlier allows remote attackers to execute arbitrary code via... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now