2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7704 | — | — | 2.7% | Apr 12, 2017 | In Wireshark 2.2.0 to 2.2.5, the DOF dissector could go into an infinite loop, triggered by packet injection or a malfor... |
| CVE-2017-7703 | — | — | 3.3% | Apr 12, 2017 | In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the IMAP dissector could crash, triggered by packet injection or a malf... |
| CVE-2017-7702 | — | — | 2.7% | Apr 12, 2017 | In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the WBXML dissector could go into an infinite loop, triggered by packet... |
| CVE-2017-7701 | — | — | 2.7% | Apr 12, 2017 | In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the BGP dissector could go into an infinite loop, triggered by packet i... |
| CVE-2017-7700 | — | — | 2.1% | Apr 12, 2017 | In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by ... |
| CVE-2017-7284 | — | — | 2.7% | Apr 12, 2017 | An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/... |
| CVE-2017-7281 | — | — | 4.3% | Apr 12, 2017 | An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createR... |
| CVE-2017-7280 | — | — | 6.2% | Apr 12, 2017 | An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not prope... |
| CVE-2017-7279 | — | — | 4.4% | Apr 12, 2017 | An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modif... |
| CVE-2017-5936 | — | — | 2.9% | Apr 12, 2017 | OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for i... |
| CVE-2017-6059 | HIGH | 7.5 | 5.2% | Apr 12, 2017 | Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.... |
| CVE-2017-7742 | — | — | 1.4% | Apr 12, 2017 | In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmenta... |
| CVE-2017-7741 | — | — | 1.2% | Apr 12, 2017 | In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmenta... |
| CVE-2017-7722 | — | — | 12.7% | Apr 12, 2017 | In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is acce... |
| CVE-2017-7719 | — | — | 2.3% | Apr 12, 2017 | SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable... |
| CVE-2017-7716 | — | — | 0.7% | Apr 12, 2017 | The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to cause a denial of servic... |
| CVE-2017-3125 | — | — | 1.1% | Apr 12, 2017 | An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute a... |
| CVE-2017-3065 | — | — | 3.4% | Apr 12, 2017 | Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitabl... |
| CVE-2017-3064 | — | — | 13.5% | Apr 12, 2017 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a sh... |
| CVE-2017-3063 | — | — | 8.9% | Apr 12, 2017 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the ActionScript2... |
| CVE-2017-3062 | — | — | 9.5% | Apr 12, 2017 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in ActionScript2 whe... |
| CVE-2017-3061 | — | — | 24.7% | Apr 12, 2017 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser... |
| CVE-2017-3060 | — | — | 7.6% | Apr 12, 2017 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the ActionScri... |
| CVE-2017-3059 | — | — | 9.5% | Apr 12, 2017 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the internal scri... |
| CVE-2017-3058 | — | — | 6.5% | Apr 12, 2017 | Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable use after free vulnerability in the sound class. ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now