2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-2675Little Snitch version 3.0 through 3.7.3 suffer from a local privilege escalation vulnerability in the installer part. Th...
CVE-2017-7192WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValid...
CVE-2017-6968GMV Checker ATM Security prior to 5.0.18 allows remote authenticated users to execute arbitrary code via unspecified vec...
CVE-2017-6130F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attac...
CVE-2017-5887WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (t...
CVE-2017-0305F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modificati...
CVE-2017-7454The iwgif_record_pixel function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to ...
CVE-2017-7453The iwgif_record_pixel function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to ...
CVE-2017-7452The iwbmp_read_info_header function in imagew-bmp.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers...
CVE-2017-7450AIRTAME HDMI dongle with firmware before 2.2.0 allows unauthenticated access to a big part of the management interface. ...
CVE-2017-7448The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers ...
CVE-2017-7447HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
CVE-2017-7446HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
CVE-2017-7444In Veritas System Recovery before 16 SP1, there is a DLL hijacking vulnerability in the patch installer if an attacker h...
CVE-2017-7443apt-cacher before 1.7.15 and apt-cacher-ng before 3.4 allow HTTP response splitting via encoded newline characters, rela...
CVE-2017-0888MEDIUM4.3Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Content-Spoofing vulnerability in the "files" app. The top navi...
CVE-2017-0887MEDIUM4.3Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing ...
CVE-2017-0886MEDIUM6.5Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application lo...
CVE-2017-0885MEDIUM4.3Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share....
CVE-2017-0884MEDIUM4.3Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permis...
CVE-2017-0883Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permissi...
CVE-2017-1180The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they...
CVE-2017-6340Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/repor...
CVE-2017-6339Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate d...
CVE-2017-6338Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow ...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now