2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-0895Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged...
CVE-2017-0894MEDIUM4.3Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical e...
CVE-2017-0893Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrust...
CVE-2017-0892LOW3.5Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password wi...
CVE-2017-0891Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading ...
CVE-2017-0890MEDIUM5.4Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search modu...
CVE-2017-8848Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.
CVE-2017-6953Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card...
CVE-2017-6051An Uncontrolled Search Path Element issue was discovered in BLF-Tech LLC VisualView HMI Version 9.9.14.0 and prior. The ...
CVE-2017-8825A null dereference vulnerability has been found in the MIME handling component of LibEtPan before 1.8, as used in MailCo...
CVE-2017-8847MEDIUM5.5The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial...
CVE-2017-8846MEDIUM5.5The read_stream function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service ...
CVE-2017-8845MEDIUM5.5The lzo1x_decompress function in lzo1x_d.ch in LZO 2.08, as used in lrzip 0.631, allows remote attackers to cause a deni...
CVE-2017-8844HIGH7.8The read_1g function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service (hea...
CVE-2017-8843MEDIUM5.5The join_pthread function in stream.c in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial of service...
CVE-2017-8842MEDIUM5.5The bufRead::get() function in libzpaq/libzpaq.h in liblrzip.so in lrzip 0.631 allows remote attackers to cause a denial...
CVE-2017-8833Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's ...
CVE-2017-8832Allen Disk 1.6 has XSS in the id parameter to downfile.php.
CVE-2017-8831MEDIUM6.4The saa7164_bus_get function in drivers/media/pci/saa7164/saa7164-bus.c in the Linux kernel through 4.11.5 allows local ...
CVE-2017-8830In ImageMagick 7.0.5-6, the ReadBMPImage function in bmp.c:1379 allows attackers to cause a denial of service (memory le...
CVE-2017-8829Deserialization vulnerability in lintian through 2.5.50.3 allows attackers to trigger code execution by requesting a rev...
CVE-2017-8827forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service...
CVE-2017-1000041Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7271. Reason: This candidate is a reservation ...
CVE-2017-1000040Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7853. Reason: This candidate is a reservation ...
CVE-2017-1000019Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-5938. Reason: This candidate is a reservation ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now