2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-6542 | — | — | 21.8% | Mar 27, 2017 | The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large ... |
| CVE-2017-6464 | — | — | 5.1% | Mar 27, 2017 | NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malf... |
| CVE-2017-6463 | — | — | 5.2% | Mar 27, 2017 | NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash... |
| CVE-2017-6462 | — | — | 0.5% | Mar 27, 2017 | Buffer overflow in the legacy Datum Programmable Time Server (DPTS) refclock driver in NTP before 4.2.8p10 and 4.3.x bef... |
| CVE-2017-6460 | — | — | 2.7% | Mar 27, 2017 | Stack-based buffer overflow in the reslist function in ntpq in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote... |
| CVE-2017-6459 | — | — | 0.4% | Mar 27, 2017 | The Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users to have unspecified impact via ... |
| CVE-2017-6458 | HIGH | 8.8 | 6.5% | Mar 27, 2017 | Multiple buffer overflows in the ctl_put* functions in NTP before 4.2.8p10 and 4.3.x before 4.3.94 allow remote authenti... |
| CVE-2017-6455 | — | — | 0.5% | Mar 27, 2017 | NTP before 4.2.8p10 and 4.3.x before 4.3.94, when using PPSAPI, allows local users to gain privileges via a DLL in the P... |
| CVE-2017-6452 | — | — | 0.4% | Mar 27, 2017 | Stack-based buffer overflow in the Windows installer for NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows local users ... |
| CVE-2017-6451 | — | — | 0.5% | Mar 27, 2017 | The mx4200_send function in the legacy MX4200 refclock in NTP before 4.2.8p10 and 4.3.x before 4.3.94 does not properly ... |
| CVE-2017-6878 | — | — | 1.0% | Mar 27, 2017 | Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web scr... |
| CVE-2017-5973 | MEDIUM | 5.5 | 0.5% | Mar 27, 2017 | The xhci_kick_epctx function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to... |
| CVE-2017-5932 | — | — | 0.4% | Mar 27, 2017 | The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a... |
| CVE-2017-5931 | HIGH | 8.8 | 0.5% | Mar 27, 2017 | Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cau... |
| CVE-2017-5899 | — | — | 1.0% | Mar 27, 2017 | Directory traversal vulnerability in the setuid root helper binary in S-nail (later S-mailx) before 14.8.16 allows local... |
| CVE-2017-5850 | — | — | 17.2% | Mar 27, 2017 | httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for ... |
| CVE-2017-5330 | — | — | 3.1% | Mar 27, 2017 | ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to as... |
| CVE-2017-6957 | — | — | 4.6% | Mar 27, 2017 | Stack-based buffer overflow in the firmware in Broadcom Wi-Fi HardMAC SoC chips, when the firmware supports CCKM Fast an... |
| CVE-2017-7269 | CRITICAL | 9.8 | 99.8% | Mar 27, 2017 | Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in... |
| CVE-2017-6069 | — | — | 0.7% | Mar 27, 2017 | Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags ... |
| CVE-2017-6068 | — | — | 0.6% | Mar 27, 2017 | Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via th... |
| CVE-2017-6067 | — | — | 0.8% | Mar 27, 2017 | Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field. |
| CVE-2017-6066 | — | — | 0.6% | Mar 27, 2017 | Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can option... |
| CVE-2017-6013 | — | — | 1.5% | Mar 27, 2017 | Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter. |
| CVE-2017-6006 | — | — | — | Mar 27, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now