2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-2683A non-privileged user of the Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could perform a ...
CVE-2017-2682The Siemens web application RUGGEDCOM NMS < V1.2 on port 8080/TCP and 8081/TCP could allow a remote attacker to perform ...
CVE-2017-6350An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does n...
CVE-2017-6349An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not pr...
CVE-2017-6344XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a c...
CVE-2017-6343The web interface on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.00...
CVE-2017-6342An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2....
CVE-2017-6341Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, a...
CVE-2017-6297The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which a...
CVE-2017-5946CRITICAL9.8The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allo...
CVE-2017-5928LOW3.7The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times ...
CVE-2017-5927Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cac...
CVE-2017-5926Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cac...
CVE-2017-5925Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cac...
CVE-2017-0037HIGH8.1Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde...
CVE-2017-2791HIGH7.5JustSystems Ichitaro 2016 Trial contains a vulnerability that exists when trying to open a specially crafted PowerPoint ...
CVE-2017-2790HIGH8.8When processing a record type of 0x3c from a Workbook stream from an Excel file (.xls), JustSystems Ichitaro Office trus...
CVE-2017-2789HIGH8.8When copying filedata into a buffer, JustSystems Ichitaro Office 2016 Trial will calculate two values to determine how m...
CVE-2017-5669HIGH7.8The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a cert...
CVE-2017-6310An issue was discovered in tnef before 1.4.13. Four type confusions have been identified in the file_add_mapi_attrs() fu...
CVE-2017-6309An issue was discovered in tnef before 1.4.13. Two type confusions have been identified in the parse_file() function. Th...
CVE-2017-6308An issue was discovered in tnef before 1.4.13. Several Integer Overflows, which can lead to Heap Overflows, have been id...
CVE-2017-6307An issue was discovered in tnef before 1.4.13. Two OOB Writes have been identified in src/mapi_attr.c:mapi_attr_read(). ...
CVE-2017-6306An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "9 of 9. Directory Traversal usin...
CVE-2017-6305An issue was discovered in ytnef before 1.9.1. This is related to a patch described as "8 of 9. Out of Bounds read and w...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now