2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-6361 | — | — | 56.8% | Mar 23, 2017 | QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors. |
| CVE-2017-6360 | — | — | 66.1% | Mar 23, 2017 | QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information ... |
| CVE-2017-6359 | — | — | 26.9% | Mar 23, 2017 | QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands vi... |
| CVE-2017-6191 | — | — | 6.7% | Mar 23, 2017 | Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename. |
| CVE-2017-5897 | CRITICAL | 9.8 | 5.0% | Mar 23, 2017 | The ip6gre_err function in net/ipv6/ip6_gre.c in the Linux kernel allows remote attackers to have unspecified impact via... |
| CVE-2017-5538 | — | — | 2.9% | Mar 23, 2017 | The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) an... |
| CVE-2017-5524 | — | — | 1.3% | Mar 23, 2017 | Plone 4.x through 4.3.11 and 5.x through 5.0.6 allow remote attackers to bypass a sandbox protection mechanism and obtai... |
| CVE-2017-5227 | — | — | 6.4% | Mar 23, 2017 | QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by... |
| CVE-2017-5207 | — | — | 0.4% | Mar 23, 2017 | Firejail before 0.9.44.4, when running a bandwidth command, allows local users to gain root privileges via the --shell a... |
| CVE-2017-5206 | — | — | 1.9% | Mar 23, 2017 | Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a secc... |
| CVE-2017-7235 | — | — | 1.5% | Mar 23, 2017 | An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that exec... |
| CVE-2017-6972 | — | — | 14.6% | Mar 22, 2017 | AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execu... |
| CVE-2017-3864 | HIGH | 8.6 | 2.7% | Mar 22, 2017 | A vulnerability in the DHCP client implementation of Cisco IOS (12.2, 12.4, and 15.0 through 15.6) and Cisco IOS XE (3.3... |
| CVE-2017-3859 | — | — | 2.5% | Mar 22, 2017 | A vulnerability in the DHCP code for the Zero Touch Provisioning feature of Cisco ASR 920 Series Aggregation Services Ro... |
| CVE-2017-3858 | — | — | 3.1% | Mar 22, 2017 | A vulnerability in the web framework of Cisco IOS XE Software could allow an authenticated, remote attacker to inject ar... |
| CVE-2017-3857 | HIGH | 7.5 | 2.6% | Mar 22, 2017 | A vulnerability in the Layer 2 Tunneling Protocol (L2TP) parsing function of Cisco IOS (12.0 through 12.4 and 15.0 throu... |
| CVE-2017-3856 | — | — | 2.5% | Mar 22, 2017 | A vulnerability in the web user interface of Cisco IOS XE 3.1 through 3.17 could allow an unauthenticated, remote attack... |
| CVE-2017-3853 | — | — | 8.7% | Mar 22, 2017 | A vulnerability in the Data-in-Motion (DMo) process installed with the Cisco IOx application environment could allow an ... |
| CVE-2017-3852 | — | — | 2.5% | Mar 22, 2017 | A vulnerability in the Cisco application-hosting framework (CAF) component of the Cisco IOx application environment coul... |
| CVE-2017-3851 | — | — | 5.2% | Mar 22, 2017 | A Directory Traversal vulnerability in the web framework code of the Cisco application-hosting framework (CAF) component... |
| CVE-2017-7231 | — | — | 1.2% | Mar 22, 2017 | pngdefry through 2017-03-22 is prone to a heap-based buffer-overflow vulnerability because it fails to properly process ... |
| CVE-2017-7230 | — | — | 13.8% | Mar 22, 2017 | A buffer overflow vulnerability in Disk Sorter Enterprise 9.5.12 and earlier allows remote attackers to execute arbitrar... |
| CVE-2017-5673 | — | — | 0.7% | Mar 22, 2017 | In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScrip... |
| CVE-2017-7227 | — | — | 2.5% | Mar 22, 2017 | GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script... |
| CVE-2017-7226 | — | — | 2.5% | Mar 22, 2017 | The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now