2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-2091 | — | — | 1.2% | Apr 28, 2017 | Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Phone Messages functi... |
| CVE-2017-2090 | — | — | 2.5% | Apr 28, 2017 | Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbi... |
| CVE-2017-7895 | CRITICAL | 9.8 | 10.8% | Apr 28, 2017 | The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lack certain checks for the end of a buff... |
| CVE-2017-8305 | — | — | 1.4% | Apr 27, 2017 | The UDFclient (before 0.8.8) custom strlcpy implementation has a buffer overflow. UDFclient's strlcpy is used only on sy... |
| CVE-2017-8308 | — | — | 1.3% | Apr 27, 2017 | In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trust... |
| CVE-2017-8307 | — | — | 1.8% | Apr 27, 2017 | In Avast Antivirus before v17, using the LPC interface API exposed by the AvastSVC.exe Windows service, it is possible t... |
| CVE-2017-8302 | — | — | 0.7% | Apr 27, 2017 | Mura CMS 7.0.6967 allows admin/?muraAction= XSS attacks, related to admin/core/views/carch/list.cfm, admin/core/views/ca... |
| CVE-2017-8301 | — | — | 1.0% | Apr 27, 2017 | LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of ... |
| CVE-2017-8298 | — | — | 0.6% | Apr 27, 2017 | cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a "Posts > Add New" action, and during creation of new t... |
| CVE-2017-8297 | — | — | 2.5% | Apr 27, 2017 | A path traversal vulnerability exists in simple-file-manager before 2017-04-26, affecting index.php (the sole "Simple PH... |
| CVE-2017-8296 | — | — | 1.4% | Apr 27, 2017 | kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history that is written in cleartext. All of the commands performed... |
| CVE-2017-5135 | — | — | 17.4% | Apr 27, 2017 | Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. T... |
| CVE-2017-8294 | — | — | 3.0% | Apr 27, 2017 | libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds re... |
| CVE-2017-5186 | — | — | 0.6% | Apr 27, 2017 | Novell iManager 2.7 before SP7 Patch 9, NetIQ iManager 3.x before 3.0.2.1, Novell eDirectory 8.8.x before 8.8 SP8 Patch ... |
| CVE-2017-3066 | CRITICAL | 9.8 | 90.6% | Apr 27, 2017 | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav... |
| CVE-2017-3008 | MEDIUM | 6.1 | 3.1% | Apr 27, 2017 | Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav... |
| CVE-2017-7415 | — | — | 4.4% | Apr 27, 2017 | Atlassian Confluence 6.x before 6.0.7 allows remote attackers to bypass authentication and read any blog or page via the... |
| CVE-2017-8291 | HIGH | 7.8 | 97.0% | Apr 27, 2017 | Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion ... |
| CVE-2017-8289 | — | — | 1.8% | Apr 27, 2017 | Stack-based buffer overflow in the ipv6_addr_from_str function in sys/net/network_layer/ipv6/addr/ipv6_addr_from_str.c i... |
| CVE-2017-8288 | — | — | 2.9% | Apr 27, 2017 | gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled ... |
| CVE-2017-8287 | — | — | 3.5% | Apr 27, 2017 | FreeType 2 before 2017-03-26 has an out-of-bounds write caused by a heap-based buffer overflow related to the t1_builder... |
| CVE-2017-6037 | — | — | 1.9% | Apr 27, 2017 | A Heap-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulner... |
| CVE-2017-6035 | — | — | 1.8% | Apr 27, 2017 | A Stack-Based Buffer Overflow issue was discovered in Wecon Technologies LEVI Studio HMI Editor before 1.8.1. This vulne... |
| CVE-2017-3162 | — | — | 6.2% | Apr 26, 2017 | HDFS clients interact with a servlet on the DataNode to browse the HDFS namespace. The NameNode is provided as a query p... |
| CVE-2017-3161 | — | — | 3.8% | Apr 26, 2017 | The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now