2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-0895 | — | — | 0.7% | May 8, 2017 | Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged... |
| CVE-2017-0894 | MEDIUM | 4.3 | 1.2% | May 8, 2017 | Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical e... |
| CVE-2017-0893 | — | — | 0.6% | May 8, 2017 | Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrust... |
| CVE-2017-0892 | LOW | 3.5 | 1.0% | May 8, 2017 | Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password wi... |
| CVE-2017-0891 | — | — | 0.6% | May 8, 2017 | Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading ... |
| CVE-2017-0890 | MEDIUM | 5.4 | 0.7% | May 8, 2017 | Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search modu... |
| CVE-2017-8848 | — | — | 0.5% | May 8, 2017 | Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password. |
| CVE-2017-6953 | — | — | 1.3% | May 8, 2017 | Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card... |
| CVE-2017-6051 | — | — | 1.4% | May 8, 2017 | An Uncontrolled Search Path Element issue was discovered in BLF-Tech LLC VisualView HMI Version 9.9.14.0 and prior. The ... |
| CVE-2017-8825 | — | — | 1.8% | May 8, 2017 | A null dereference vulnerability has been found in the MIME handling component of LibEtPan before 1.8, as used in MailCo... |
| CVE-2017-8847 | MEDIUM | 5.5 | 1.4% | May 8, 2017 | The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial... |
| CVE-2017-8846 | MEDIUM | 5.5 | 1.6% | May 8, 2017 | The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service ... |
| CVE-2017-8845 | MEDIUM | 5.5 | 1.4% | May 8, 2017 | The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a deni... |
| CVE-2017-8844 | HIGH | 7.8 | 1.6% | May 8, 2017 | The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (hea... |
| CVE-2017-8843 | MEDIUM | 5.5 | 1.4% | May 8, 2017 | The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service... |
| CVE-2017-8842 | MEDIUM | 5.5 | 1.6% | May 8, 2017 | The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial... |
| CVE-2017-8833 | — | — | 0.7% | May 8, 2017 | Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's ... |
| CVE-2017-8832 | — | — | 0.6% | May 8, 2017 | Allen Disk 1.6 has XSS in the id parameter to downfile.php. |
| CVE-2017-8831 | MEDIUM | 6.4 | 0.4% | May 8, 2017 | The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local ... |
| CVE-2017-8830 | — | — | 1.5% | May 8, 2017 | In ImageMagick 7.0.5-6, the ReadBMPImage function in bmp.c:1379 allows attackers to cause a denial of service (memory le... |
| CVE-2017-8829 | — | — | 1.5% | May 8, 2017 | Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a rev... |
| CVE-2017-8827 | — | — | 1.6% | May 8, 2017 | forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service... |
| CVE-2017-1000041 | — | — | — | May 7, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7271. Reason: This candidate is a reservation ... |
| CVE-2017-1000040 | — | — | — | May 7, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7853. Reason: This candidate is a reservation ... |
| CVE-2017-1000019 | — | — | — | May 7, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-5938. Reason: This candidate is a reservation ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now