2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-6975 | — | — | 0.5% | Apr 5, 2017 | Wi-Fi in Apple iOS before 10.3.1 does not prevent CVE-2017-6956 stack buffer overflow exploitation via a crafted access ... |
| CVE-2017-6956 | — | — | 2.0% | Apr 5, 2017 | On the Broadcom Wi-Fi HardMAC SoC with fbt firmware, a stack buffer overflow occurs when handling an 802.11r (FT) authen... |
| CVE-2017-0339 | — | — | 1.8% | Apr 5, 2017 | An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execut... |
| CVE-2017-0332 | — | — | 2.1% | Apr 5, 2017 | An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execut... |
| CVE-2017-0330 | — | — | 1.1% | Apr 5, 2017 | An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access... |
| CVE-2017-0329 | — | — | 2.1% | Apr 5, 2017 | An elevation of privilege vulnerability in the NVIDIA boot and power management processor driver could enable a local ma... |
| CVE-2017-0328 | — | — | 1.2% | Apr 5, 2017 | An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access... |
| CVE-2017-0327 | — | — | 1.8% | Apr 5, 2017 | An elevation of privilege vulnerability in the NVIDIA crypto driver could enable a local malicious application to execut... |
| CVE-2017-0325 | — | — | 1.8% | Apr 5, 2017 | An elevation of privilege vulnerability in the NVIDIA I2C HID driver could enable a local malicious application to execu... |
| CVE-2017-7358 | — | — | 2.7% | Apr 5, 2017 | In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrar... |
| CVE-2017-2671 | — | — | 1.5% | Apr 5, 2017 | The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock a... |
| CVE-2017-5649 | — | — | 2.8% | Apr 4, 2017 | Apache Geode before 1.1.1, when a cluster has enabled security by setting the security-manager property, allows remote a... |
| CVE-2017-7418 | — | — | 0.4% | Apr 4, 2017 | ProFTPD before 1.3.5e and 1.3.6 before 1.3.6rc5 controls whether the home directory of a user could contain a symbolic l... |
| CVE-2017-7234 | — | — | 1.8% | Apr 4, 2017 | A maliciously crafted URL to a Django (1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18) site using the ``dj... |
| CVE-2017-7233 | — | — | 2.4% | Apr 4, 2017 | Django 1.10 before 1.10.7, 1.9 before 1.9.13, and 1.8 before 1.8.18 relies on user input in some cases to redirect the u... |
| CVE-2017-0360 | — | — | 1.5% | Apr 4, 2017 | file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitra... |
| CVE-2017-7307 | — | — | 0.3% | Apr 4, 2017 | Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physic... |
| CVE-2017-7306 | MEDIUM | 6.4 | 0.4% | Apr 4, 2017 | Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proxi... |
| CVE-2017-7305 | MEDIUM | 4.6 | 0.3% | Apr 4, 2017 | Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attac... |
| CVE-2017-5670 | — | — | 0.4% | Apr 4, 2017 | Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for p... |
| CVE-2017-7414 | — | — | 1.2% | Apr 4, 2017 | In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition 5.x through 5.2.17, OS Command Injection can occ... |
| CVE-2017-7413 | — | — | 40.4% | Apr 4, 2017 | In Horde_Crypt before 2.7.6, as used in Horde Groupware Webmail Edition through 5.2.17, OS Command Injection can occur i... |
| CVE-2017-7398 | — | — | 3.0% | Apr 4, 2017 | D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacke... |
| CVE-2017-7228 | — | — | 1.6% | Apr 4, 2017 | An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The e... |
| CVE-2017-5683 | — | — | 0.4% | Apr 4, 2017 | Privilege escalation in IntelHAXM.sys driver in the Intel Hardware Accelerated Execution Manager before version 6.0.6 al... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now