2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-15854 | — | — | 0.2% | Jun 12, 2018 | The value of fix_param->num_chans is received from firmware and if it is too large, an integer overflow can occur in wma... |
| CVE-2017-15843 | — | — | 0.1% | Jun 12, 2018 | Due to a race condition in a bus driver, a double free in msm_bus_floor_vote_context() can potentially occur in all Andr... |
| CVE-2017-15842 | — | — | 0.2% | Jun 12, 2018 | Buffer might get used after it gets freed due to unlocking the mutex before freeing the buffer in all Android releases f... |
| CVE-2017-18291 | — | — | 1.0% | Jun 12, 2018 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET user parameter. |
| CVE-2017-18290 | — | — | 1.0% | Jun 12, 2018 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET sort_direction parame... |
| CVE-2017-18289 | — | — | 1.0% | Jun 12, 2018 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter. |
| CVE-2017-18288 | — | — | 1.0% | Jun 12, 2018 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET game parameter. |
| CVE-2017-18287 | — | — | 1.0% | Jun 12, 2018 | An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search paramete... |
| CVE-2017-7848 | — | — | 1.8% | Jun 11, 2018 | RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects... |
| CVE-2017-7847 | — | — | 1.6% | Jun 11, 2018 | Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affec... |
| CVE-2017-7846 | — | — | 2.0% | Jun 11, 2018 | It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed... |
| CVE-2017-7845 | — | — | 3.2% | Jun 11, 2018 | A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used fo... |
| CVE-2017-7844 | — | — | 1.8% | Jun 11, 2018 | A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image ca... |
| CVE-2017-7843 | — | — | 3.0% | Jun 11, 2018 | When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprin... |
| CVE-2017-7842 | — | — | 1.6% | Jun 11, 2018 | If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" e... |
| CVE-2017-7840 | — | — | 1.1% | Jun 11, 2018 | JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved b... |
| CVE-2017-7839 | — | — | 1.1% | Jun 11, 2018 | Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be i... |
| CVE-2017-7838 | — | — | 1.5% | Jun 11, 2018 | Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-doma... |
| CVE-2017-7837 | — | — | 1.5% | Jun 11, 2018 | SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerabili... |
| CVE-2017-7836 | — | — | 0.3% | Jun 11, 2018 | The "pingsender" executable used by the Firefox Health Report dynamically loads a system copy of libcurl, which an attac... |
| CVE-2017-7835 | — | — | 1.5% | Jun 11, 2018 | Mixed content blocking of insecure (HTTP) sub-resources in a secure (HTTPS) document was not correctly applied for resou... |
| CVE-2017-7834 | — | — | 1.5% | Jun 11, 2018 | A "data:" URL loaded in a new tab did not inherit the Content Security Policy (CSP) of the original page, allowing for b... |
| CVE-2017-7833 | — | — | 1.5% | Jun 11, 2018 | Some Arabic and Indic vowel marker characters can be combined with Latin characters in a domain name to eclipse the non-... |
| CVE-2017-7832 | — | — | 1.5% | Jun 11, 2018 | The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or... |
| CVE-2017-7831 | — | — | 1.6% | Jun 11, 2018 | A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_expose... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now