2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5336 | — | — | 7.1% | Mar 24, 2017 | Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x b... |
| CVE-2017-5335 | — | — | 8.1% | Mar 24, 2017 | The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote at... |
| CVE-2017-5334 | — | — | 32.8% | Mar 24, 2017 | Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 al... |
| CVE-2017-6087 | — | — | 7.2% | Mar 24, 2017 | EyesOfNetwork ("EON") 5.0 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacte... |
| CVE-2017-5869 | — | — | 34.6% | Mar 24, 2017 | Directory traversal vulnerability in the file import feature in Nuxeo Platform 6.0, 7.1, 7.2, and 7.3 allows remote auth... |
| CVE-2017-5644 | — | — | 4.6% | Mar 24, 2017 | Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via ... |
| CVE-2017-6369 | HIGH | 8.8 | 3.3% | Mar 24, 2017 | Insufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and 3.0.x before 3.0.2 allow remote authenticate... |
| CVE-2017-2577 | — | — | — | Mar 24, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-6507 | — | — | 1.6% | Mar 24, 2017 | An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init script... |
| CVE-2017-5199 | — | — | 2.9% | Mar 24, 2017 | The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary... |
| CVE-2017-5198 | — | — | 0.9% | Mar 24, 2017 | SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root acce... |
| CVE-2017-7251 | MEDIUM | 6.1 | 1.0% | Mar 23, 2017 | A Cross-Site Scripting (XSS) was discovered in pi-engine/pi 2.5.0. The vulnerability exists due to insufficient filtrati... |
| CVE-2017-7250 | — | — | 1.1% | Mar 23, 2017 | A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient f... |
| CVE-2017-7249 | — | — | 1.1% | Mar 23, 2017 | Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insuf... |
| CVE-2017-7248 | — | — | 1.1% | Mar 23, 2017 | A Cross-Site Scripting (XSS) was discovered in Gazelle before 2017-03-19. The vulnerability exists due to insufficient f... |
| CVE-2017-7247 | — | — | 1.1% | Mar 23, 2017 | Multiple Cross-Site Scripting (XSS) were discovered in Gazelle before 2017-03-19. The vulnerabilities exist due to insuf... |
| CVE-2017-7246 | — | — | 2.6% | Mar 23, 2017 | Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote a... |
| CVE-2017-7245 | — | — | 2.2% | Mar 23, 2017 | Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote a... |
| CVE-2017-7244 | — | — | 2.0% | Mar 23, 2017 | The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of servi... |
| CVE-2017-6950 | — | — | 3.8% | Mar 23, 2017 | SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary co... |
| CVE-2017-6911 | — | — | 0.6% | Mar 23, 2017 | USB Pratirodh is prone to sensitive information disclosure. It stores sensitive information such as username and passwor... |
| CVE-2017-6895 | — | — | 3.0% | Mar 23, 2017 | USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml. |
| CVE-2017-6517 | — | — | 46.3% | Mar 23, 2017 | Microsoft Skype 7.16.0.102 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbi... |
| CVE-2017-7242 | — | — | 0.8% | Mar 23, 2017 | Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: t... |
| CVE-2017-7199 | — | — | 0.4% | Mar 23, 2017 | Nessus 6.6.2 - 6.10.3 contains a flaw related to insecure permissions that may allow a local attacker to escalate privil... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now