2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-7294 | HIGH | 7.8 | 0.4% | Mar 29, 2017 | The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.6 does... |
| CVE-2017-6864 | — | — | 0.7% | Mar 29, 2017 | The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow an authenticated user ... |
| CVE-2017-2689 | — | — | 1.4% | Mar 29, 2017 | Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at... |
| CVE-2017-2688 | — | — | 1.1% | Mar 29, 2017 | The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow remote attackers to pe... |
| CVE-2017-2687 | — | — | 1.0% | Mar 29, 2017 | Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is p... |
| CVE-2017-2686 | — | — | 1.1% | Mar 29, 2017 | Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary ... |
| CVE-2017-7297 | HIGH | 8.8 | 1.5% | Mar 29, 2017 | Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This i... |
| CVE-2017-7277 | — | — | 0.4% | Mar 28, 2017 | The TCP stack in the Linux kernel through 4.10.6 mishandles the SCM_TIMESTAMPING_OPT_STATS feature, which allows local u... |
| CVE-2017-0882 | — | — | 1.1% | Mar 28, 2017 | Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix ... |
| CVE-2017-0881 | — | — | 1.1% | Mar 28, 2017 | An error in the implementation of an autosubscribe feature in the check_stream_exists route of the Zulip group chat appl... |
| CVE-2017-6964 | HIGH | 7.8 | 0.5% | Mar 28, 2017 | dmcrypt-get-device, as shipped in the eject package of Debian and Ubuntu, does not check the return value of the (1) set... |
| CVE-2017-1153 | — | — | 1.3% | Mar 27, 2017 | IBM TRIRIGA Report Manager 3.2 through 3.5 contains a vulnerability that could allow an authenticated user to execute ac... |
| CVE-2017-1143 | — | — | 0.9% | Mar 27, 2017 | IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by t... |
| CVE-2017-1142 | — | — | 1.2% | Mar 27, 2017 | IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by t... |
| CVE-2017-1120 | — | — | 1.0% | Mar 27, 2017 | IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2017-5239 | — | — | 0.5% | Mar 27, 2017 | Due to a lack of standard encryption when transmitting sensitive information over the internet to a centralized monitori... |
| CVE-2017-5238 | — | — | 0.9% | Mar 27, 2017 | Due to a lack of bounds checking, several input configuration fields for the Eview EV-07S GPS Tracker will overflow data... |
| CVE-2017-5237 | — | — | 2.0% | Mar 27, 2017 | Due to a lack of authentication, an unauthenticated user who knows the Eview EV-07S GPS Tracker's phone number can rever... |
| CVE-2017-7275 | — | — | 1.4% | Mar 27, 2017 | The ReadPCXImage function in coders/pcx.c in ImageMagick 7.0.4.9 allows remote attackers to cause a denial of service (a... |
| CVE-2017-7274 | — | — | 1.6% | Mar 27, 2017 | The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to cause a denial of serv... |
| CVE-2017-7273 | — | — | 0.5% | Mar 27, 2017 | The cp_report_fixup function in drivers/hid/hid-cypress.c in the Linux kernel 3.2 and 4.x before 4.9.4 allows physically... |
| CVE-2017-7272 | — | — | 3.5% | Mar 27, 2017 | PHP through 7.1.11 enables potential SSRF in applications that accept an fsockopen or pfsockopen hostname argument with ... |
| CVE-2017-7271 | — | — | 1.0% | Mar 27, 2017 | Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows... |
| CVE-2017-7191 | — | — | 3.4% | Mar 27, 2017 | The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and poss... |
| CVE-2017-7183 | — | — | 5.9% | Mar 27, 2017 | The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now