2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-18371 | — | — | 22.5% | May 2, 2019 | The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passw... |
| CVE-2017-18370 | — | — | 22.9% | May 2, 2019 | The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in t... |
| CVE-2017-18369 | — | — | 67.6% | May 2, 2019 | The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote ... |
| CVE-2017-18368 | CRITICAL | 9.8 | 94.5% | May 2, 2019 | The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command inject... |
| CVE-2017-16558 | — | — | 1.2% | Apr 25, 2019 | Contao 3.0.0 to 3.5.30 and 4.0.0 to 4.4.7 contains an SQL injection vulnerability in the back end as well as in the list... |
| CVE-2017-18367 | — | — | 2.5% | Apr 24, 2019 | libseccomp-golang 0.9.0 and earlier incorrectly generates BPFs that OR multiple arguments rather than ANDing them. A pro... |
| CVE-2017-15716 | — | — | — | Apr 23, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n... |
| CVE-2017-12619 | — | — | 4.9% | Apr 23, 2019 | Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to hijack a valid user sessi... |
| CVE-2017-11430 | HIGH | 7.7 | 2.3% | Apr 17, 2019 | OmniAuth OmnitAuth-SAML 1.9.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization ... |
| CVE-2017-11429 | HIGH | 7.7 | 2.4% | Apr 17, 2019 | Clever saml2-js 2.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in su... |
| CVE-2017-11428 | HIGH | 7.7 | 2.5% | Apr 17, 2019 | OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs ... |
| CVE-2017-11427 | HIGH | 7.7 | 4.4% | Apr 17, 2019 | OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs... |
| CVE-2017-7777 | — | — | 1.2% | Apr 15, 2019 | Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph funct... |
| CVE-2017-7776 | — | — | 2.8% | Apr 15, 2019 | Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph. |
| CVE-2017-7774 | — | — | 1.4% | Apr 15, 2019 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function. |
| CVE-2017-7773 | — | — | 1.4% | Apr 15, 2019 | Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor. |
| CVE-2017-7771 | — | — | 1.2% | Apr 15, 2019 | Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function. |
| CVE-2017-18366 | — | — | 0.7% | Apr 15, 2019 | Subrion CMS 4.1.5 has CSRF in blog/delete/. |
| CVE-2017-7775 | — | — | — | Apr 15, 2019 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2017-7772 | — | — | 1.4% | Apr 12, 2019 | Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function. |
| CVE-2017-14199 | — | — | 1.7% | Apr 12, 2019 | A buffer overflow has been found in the Zephyr Project's getaddrinfo() implementation in 1.9.0 and 1.10.0. |
| CVE-2017-3139 | HIGH | 7.5 | 1.6% | Apr 9, 2019 | A denial of service flaw was found in the way BIND handled DNSSEC validation. A remote attacker could use this flaw to m... |
| CVE-2017-17023 | — | — | 0.6% | Apr 9, 2019 | The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected cli... |
| CVE-2017-17544 | HIGH | 7.2 | 1.7% | Apr 9, 2019 | A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin use... |
| CVE-2017-7912 | — | — | 4.8% | Apr 8, 2019 | Hanwha Techwin SRN-4000, SRN-4000 firmware versions prior to SRN4000_v2.16_170401, A specially crafted http request and ... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now