2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-8072 | — | — | 0.4% | Apr 23, 2017 | The cp2112_gpio_direction_input function in drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 does not hav... |
| CVE-2017-8071 | — | — | 0.4% | Apr 23, 2017 | drivers/hid/hid-cp2112.c in the Linux kernel 4.9.x before 4.9.9 uses a spinlock without considering that sleeping is pos... |
| CVE-2017-8070 | — | — | 0.4% | Apr 23, 2017 | drivers/net/usb/catc.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK option, ... |
| CVE-2017-8069 | — | — | 0.4% | Apr 23, 2017 | drivers/net/usb/rtl8150.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK optio... |
| CVE-2017-8068 | — | — | 0.5% | Apr 23, 2017 | drivers/net/usb/pegasus.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK optio... |
| CVE-2017-8067 | HIGH | 7.8 | 0.4% | Apr 23, 2017 | drivers/char/virtio_console.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CONFIG_... |
| CVE-2017-8066 | — | — | 0.4% | Apr 23, 2017 | drivers/net/can/usb/gs_usb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.2 interacts incorrectly with the CONFIG_VM... |
| CVE-2017-8065 | — | — | 0.4% | Apr 23, 2017 | crypto/ccm.c in the Linux kernel 4.9.x and 4.10.x through 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK optio... |
| CVE-2017-8064 | HIGH | 7.8 | 0.4% | Apr 23, 2017 | drivers/media/usb/dvb-usb-v2/dvb_usb_core.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly wi... |
| CVE-2017-8063 | HIGH | 7.8 | 0.4% | Apr 23, 2017 | drivers/media/usb/dvb-usb/cxusb.c in the Linux kernel 4.9.x and 4.10.x before 4.10.12 interacts incorrectly with the CON... |
| CVE-2017-8062 | HIGH | 7.8 | 0.4% | Apr 23, 2017 | drivers/media/usb/dvb-usb/dw2102.c in the Linux kernel 4.9.x and 4.10.x before 4.10.4 interacts incorrectly with the CON... |
| CVE-2017-8061 | — | — | 0.4% | Apr 23, 2017 | drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and 4.10.x before 4.10.7 interacts incorrectly wi... |
| CVE-2017-8056 | — | — | 5.1% | Apr 22, 2017 | WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC a... |
| CVE-2017-8055 | — | — | 1.6% | Apr 22, 2017 | WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a... |
| CVE-2017-8054 | — | — | 1.1% | Apr 22, 2017 | The function PdfPagesTree::GetPageNodeFromArray in PdfPageTree.cpp:464 in PoDoFo 0.9.5 allows remote attackers to cause ... |
| CVE-2017-8053 | — | — | 0.9% | Apr 22, 2017 | PoDoFo 0.9.5 allows denial of service (infinite recursion and stack consumption) via a crafted PDF file in PoDoFo::PdfPa... |
| CVE-2017-8052 | — | — | 0.7% | Apr 22, 2017 | Craft CMS before 2.6.2974 allows XSS attacks. |
| CVE-2017-7991 | — | — | 2.1% | Apr 22, 2017 | Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function ... |
| CVE-2017-8051 | — | — | 16.5% | Apr 21, 2017 | Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI.... |
| CVE-2017-8050 | — | — | 0.9% | Apr 21, 2017 | Tenable Appliance 4.4.0, and possibly prior, contains a flaw in the Web UI that allows for the unauthorized manipulation... |
| CVE-2017-7994 | — | — | 2.6% | Apr 21, 2017 | The function TextExtractor::ExtractText in TextExtractor.cpp:77 in PoDoFo 0.9.5 allows remote attackers to cause a denia... |
| CVE-2017-7992 | — | — | 0.7% | Apr 21, 2017 | Heartland Payment Systems Payment Gateway PHP SDK hps/heartland-php v2.8.17 is vulnerable to a reflected XSS in examples... |
| CVE-2017-7951 | — | — | 0.6% | Apr 21, 2017 | WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context. |
| CVE-2017-7409 | — | — | 1.0% | Apr 21, 2017 | Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, ... |
| CVE-2017-7220 | — | — | 2.0% | Apr 21, 2017 | OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now