2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-6361QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
CVE-2017-6360QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information ...
CVE-2017-6359QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands vi...
CVE-2017-6191Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename.
CVE-2017-5897CRITICAL9.8The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via...
CVE-2017-5538The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) an...
CVE-2017-5524Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtai...
CVE-2017-5227QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by...
CVE-2017-5207Firejail before 0.9.44.4, when running a bandwidth command, allows local users to gain root privileges via the --shell a...
CVE-2017-5206Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a secc...
CVE-2017-7235An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that exec...
CVE-2017-6972AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execu...
CVE-2017-3864HIGH8.6A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3...
CVE-2017-3859A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Ro...
CVE-2017-3858A vulnerability in the web framework of Cisco IOS XE Software could allow an authenticated, remote attacker to inject ar...
CVE-2017-3857HIGH7.5A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through 12.4 and 15.0 throu...
CVE-2017-3856A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attack...
CVE-2017-3853A vulnerability in the Data-in-Motion (DMo) process installed with the Cisco IOx application environment could allow an ...
CVE-2017-3852A vulnerability in the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment coul...
CVE-2017-3851A Directory Traversal vulnerability in the web framework code of the Cisco application-hosting framework (CAF) component...
CVE-2017-7231pngdefry through 2017-03-22 is prone to a heap-based buffer-overflow vulnerability because it fails to properly process ...
CVE-2017-7230A buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrar...
CVE-2017-5673In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScrip...
CVE-2017-7227GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script...
CVE-2017-7226The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2....

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now