2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-2675 | — | — | 0.3% | Apr 6, 2017 | Little Snitch version 3.0 through 3.7.3 suffer from a local privilege escalation vulnerability in the installer part. Th... |
| CVE-2017-7192 | — | — | 1.9% | Apr 6, 2017 | WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValid... |
| CVE-2017-6968 | — | — | 2.3% | Apr 6, 2017 | GMV Checker ATM Security prior to 5.0.18 allows remote authenticated users to execute arbitrary code via unspecified vec... |
| CVE-2017-6130 | — | — | 1.1% | Apr 6, 2017 | F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attac... |
| CVE-2017-5887 | — | — | 1.4% | Apr 6, 2017 | WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (t... |
| CVE-2017-0305 | — | — | 3.8% | Apr 6, 2017 | F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modificati... |
| CVE-2017-7454 | — | — | 1.1% | Apr 6, 2017 | The iwgif_record_pixel function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to ... |
| CVE-2017-7453 | — | — | 1.1% | Apr 6, 2017 | The iwgif_record_pixel function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to ... |
| CVE-2017-7452 | — | — | 1.1% | Apr 6, 2017 | The iwbmp_read_info_header function in imagew-bmp.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers... |
| CVE-2017-7450 | — | — | 1.4% | Apr 5, 2017 | AIRTAME HDMI dongle with firmware before 2.2.0 allows unauthenticated access to a big part of the management interface. ... |
| CVE-2017-7448 | — | — | 1.2% | Apr 5, 2017 | The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers ... |
| CVE-2017-7447 | — | — | 3.5% | Apr 5, 2017 | HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code. |
| CVE-2017-7446 | — | — | 3.1% | Apr 5, 2017 | HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges. |
| CVE-2017-7444 | — | — | 1.1% | Apr 5, 2017 | In Veritas System Recovery before 16 SP1, there is a DLL hijacking vulnerability in the patch installer if an attacker h... |
| CVE-2017-7443 | — | — | 0.7% | Apr 5, 2017 | apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, rela... |
| CVE-2017-0888 | MEDIUM | 4.3 | 1.5% | Apr 5, 2017 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navi... |
| CVE-2017-0887 | MEDIUM | 4.3 | 0.9% | Apr 5, 2017 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing ... |
| CVE-2017-0886 | MEDIUM | 6.5 | 1.2% | Apr 5, 2017 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application lo... |
| CVE-2017-0885 | MEDIUM | 4.3 | 0.9% | Apr 5, 2017 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share.... |
| CVE-2017-0884 | MEDIUM | 4.3 | 0.7% | Apr 5, 2017 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permis... |
| CVE-2017-0883 | — | — | 0.6% | Apr 5, 2017 | Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permissi... |
| CVE-2017-1180 | — | — | 0.7% | Apr 5, 2017 | The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they... |
| CVE-2017-6340 | — | — | 2.5% | Apr 5, 2017 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/repor... |
| CVE-2017-6339 | — | — | 4.1% | Apr 5, 2017 | Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate d... |
| CVE-2017-6338 | — | — | 3.9% | Apr 5, 2017 | Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now