2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-3204 | HIGH | 8.1 | 3.2% | Apr 4, 2017 | The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default ... |
| CVE-2017-7412 | HIGH | 7.8 | 0.4% | Apr 4, 2017 | NixOS 17.03 before 17.03.887 has a world-writable Docker socket, which allows local users to gain privileges by executin... |
| CVE-2017-7410 | CRITICAL | 9.8 | 2.9% | Apr 3, 2017 | Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier ... |
| CVE-2017-5686 | — | — | 0.3% | Apr 3, 2017 | The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version SY0059 may allow may allow an atta... |
| CVE-2017-5685 | — | — | 0.3% | Apr 3, 2017 | The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version KY0045 may allow may allow an atta... |
| CVE-2017-5684 | — | — | 0.3% | Apr 3, 2017 | The BIOS in Intel Compute Stick systems based on 6th Gen Intel Core processors prior to version CC047 may allow an attac... |
| CVE-2017-7407 | LOW | 2.4 | 0.6% | Apr 3, 2017 | The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitiv... |
| CVE-2017-7397 | — | — | 11.1% | Apr 3, 2017 | BackBox Linux 4.6 allows remote attackers to cause a denial of service (ksoftirqd CPU consumption) via a flood of packet... |
| CVE-2017-7402 | — | — | 5.0% | Apr 3, 2017 | Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/ind... |
| CVE-2017-5642 | — | — | 1.9% | Apr 3, 2017 | During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs. |
| CVE-2017-7401 | — | — | 4.0% | Apr 3, 2017 | Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and ea... |
| CVE-2017-7400 | — | — | 1.1% | Apr 3, 2017 | OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to condu... |
| CVE-2017-7383 | — | — | 1.3% | Apr 3, 2017 | The PdfFontFactory.cpp:195:62 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer de... |
| CVE-2017-7382 | — | — | 1.3% | Apr 3, 2017 | The PdfFontFactory.cpp:200:88 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer de... |
| CVE-2017-7381 | — | — | 1.3% | Apr 3, 2017 | The doc/PdfPage.cpp:609:23 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer deref... |
| CVE-2017-7380 | — | — | 1.4% | Apr 3, 2017 | The doc/PdfPage.cpp:614:20 code in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer deref... |
| CVE-2017-7379 | — | — | 1.3% | Apr 3, 2017 | The PoDoFo::PdfSimpleEncoding::ConvertToEncoding function in PdfEncoding.cpp in PoDoFo 0.9.5 allows remote attackers to ... |
| CVE-2017-7378 | — | — | 1.3% | Apr 3, 2017 | The PoDoFo::PdfPainter::ExpandTabs function in PdfPainter.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial ... |
| CVE-2017-6448 | — | — | 1.7% | Apr 3, 2017 | The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allows remote attackers to cause a denial of... |
| CVE-2017-6441 | — | — | 1.8% | Apr 3, 2017 | The _zval_get_long_func_ex in Zend/zend_operators.c in PHP 7.1.2 allows attackers to cause a denial of service (NULL poi... |
| CVE-2017-6194 | — | — | 1.9% | Apr 3, 2017 | The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote attackers to cause a denial of service (heap... |
| CVE-2017-6181 | — | — | 3.6% | Apr 3, 2017 | The parse_char_class function in regparse.c in the Onigmo (aka Oniguruma-mod) regular expression library, as used in Rub... |
| CVE-2017-5951 | — | — | 1.9% | Apr 3, 2017 | The mem_get_bits_rectangle function in base/gdevmem.c in Artifex Software, Inc. Ghostscript 9.20 allows remote attackers... |
| CVE-2017-5950 | — | — | 2.0% | Apr 3, 2017 | The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.3 allows remote attackers to cause a denial o... |
| CVE-2017-5949 | — | — | 1.8% | Apr 3, 2017 | JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a den... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now