2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-5857 | MEDIUM | 6.5 | 0.4% | Mar 16, 2017 | Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows l... |
| CVE-2017-5856 | MEDIUM | 6.5 | 0.4% | Mar 16, 2017 | Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS ... |
| CVE-2017-5667 | MEDIUM | 6.5 | 0.4% | Mar 16, 2017 | The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privil... |
| CVE-2017-5643 | — | — | 4.9% | Mar 16, 2017 | Apache Camel's Validation Component is vulnerable against SSRF via remote DTDs and XXE. |
| CVE-2017-5617 | HIGH | 7.4 | 2.0% | Mar 16, 2017 | The SVG Salamander (aka svgSalamander) library, when used in a web application, allows remote attackers to conduct serve... |
| CVE-2017-5505 | — | — | 2.1% | Mar 16, 2017 | The jas_matrix_asl function in jas_seq.c in JasPer 1.900.27 allows remote attackers to cause a denial of service (invali... |
| CVE-2017-6510 | — | — | 15.3% | Mar 16, 2017 | Easy File Sharing FTP Server version 3.6 is vulnerable to a directory traversal vulnerability which allows an attacker t... |
| CVE-2017-6381 | — | — | 3.9% | Mar 16, 2017 | A 3rd party development library including with Drupal 8 development dependencies is vulnerable to remote code execution.... |
| CVE-2017-6379 | — | — | 0.8% | Mar 16, 2017 | Some administrative paths in Drupal 8.2.x before 8.2.7 did not include protection for CSRF. This would allow an attacker... |
| CVE-2017-6377 | — | — | 1.9% | Mar 16, 2017 | When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for t... |
| CVE-2017-6061 | — | — | 1.6% | Mar 16, 2017 | Cross-site scripting (XSS) vulnerability in the help component of SAP BusinessObjects Financial Consolidation 10.0.0.193... |
| CVE-2017-6023 | CRITICAL | 9.8 | 4.4% | Mar 16, 2017 | An issue was discovered in Fatek Automation PLC Ethernet Module. The affected Ether_cfg software configuration tool runs... |
| CVE-2017-6461 | — | — | — | Mar 15, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-6457 | — | — | — | Mar 15, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-6456 | — | — | — | Mar 15, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-6454 | — | — | — | Mar 15, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-6453 | — | — | — | Mar 15, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2017-3854 | HIGH | 8.8 | 1.4% | Mar 15, 2017 | A vulnerability in the mesh code of Cisco Wireless LAN Controller (WLC) software could allow an unauthenticated, remote ... |
| CVE-2017-3846 | — | — | 2.0% | Mar 15, 2017 | A vulnerability in the Client Manager Server of Cisco Workload Automation and Cisco Tidal Enterprise Scheduler could all... |
| CVE-2017-3831 | — | — | 5.3% | Mar 15, 2017 | A vulnerability in the web-based GUI of Cisco Mobility Express 1800 Series Access Points could allow an unauthenticated,... |
| CVE-2017-3819 | — | — | 3.3% | Mar 15, 2017 | A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR 50... |
| CVE-2017-5937 | — | — | 0.4% | Mar 15, 2017 | The util_format_is_pure_uint function in vrend_renderer.c in Virgil 3d project (aka virglrenderer) 0.6.0 and earlier all... |
| CVE-2017-5898 | MEDIUM | 5.5 | 0.4% | Mar 15, 2017 | Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when b... |
| CVE-2017-5849 | — | — | 1.9% | Mar 15, 2017 | tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers... |
| CVE-2017-6918 | — | — | 0.4% | Mar 15, 2017 | CSRF exists in BigTree CMS 4.2.16 with the value[#][*] parameter to the admin/settings/update/ page. The Navigation Soci... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now