2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-6975Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access ...
CVE-2017-6956On the Broadcom Wi-Fi HardMAC SoC with fbt firmware, a stack buffer overflow occurs when handling an 802.11r (FT) authen...
CVE-2017-0339An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execut...
CVE-2017-0332An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execut...
CVE-2017-0330An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access...
CVE-2017-0329An elevation of privilege vulnerability in the NVIDIA boot and power management processor driver could enable a local ma...
CVE-2017-0328An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access...
CVE-2017-0327An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execut...
CVE-2017-0325An elevation of privilege vulnerability in the NVIDIA I2C HID driver could enable a local malicious application to execu...
CVE-2017-7358In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrar...
CVE-2017-2671The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock a...
CVE-2017-5649Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote a...
CVE-2017-7418ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic l...
CVE-2017-7234A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``dj...
CVE-2017-7233Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the u...
CVE-2017-0360file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitra...
CVE-2017-7307Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physic...
CVE-2017-7306MEDIUM6.4Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proxi...
CVE-2017-7305MEDIUM4.6Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attac...
CVE-2017-5670Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for p...
CVE-2017-7414In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occ...
CVE-2017-7413In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur i...
CVE-2017-7398D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacke...
CVE-2017-7228An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The e...
CVE-2017-5683Privilege escalation in IntelHAXM.sys driver in the Intel Hardware Accelerated Execution Manager before version 6.0.6 al...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now