2017 CVE Vulnerabilities

17,105 CVEs published in 2017.

CVE IDSeverityCVSSDescription
CVE-2017-0408A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbit...
CVE-2017-0407A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause me...
CVE-2017-0406A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause me...
CVE-2017-0405A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially crafted file to cause...
CVE-2017-5677PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code...
CVE-2017-5595A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of ...
CVE-2017-5368ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forger...
CVE-2017-5367Multiple reflected XSS vulnerabilities exist within form and link input parameters of ZoneMinder v1.30 and v1.29, an ope...
CVE-2017-5879An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated u...
CVE-2017-5877XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction param...
CVE-2017-5876XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.
CVE-2017-5875XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter.
CVE-2017-5577The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 d...
CVE-2017-5576HIGH7.8Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux k...
CVE-2017-5551The simple_set_acl function in fs/posix_acl.c in the Linux kernel before 4.9.6 preserves the setgid bit during a setxatt...
CVE-2017-5550Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to o...
CVE-2017-5549The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitia...
CVE-2017-5548drivers/net/ieee802154/atusb.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK o...
CVE-2017-5547HIGH7.8drivers/hid/hid-corsair.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option...
CVE-2017-5546HIGH7.8The freelist-randomization feature in mm/slab.c in the Linux kernel 4.8.x and 4.9.x before 4.9.5 allows local users to c...
CVE-2017-2596The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXO...
CVE-2017-2583The load_segment_descriptor implementation in arch/x86/kvm/emulate.c in the Linux kernel before 4.9.5 improperly emulate...
CVE-2017-5137An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the S...
CVE-2017-5136An issue was discovered on SendQuick Entera and Avera devices before 2HF16. The application failed to check the access c...
CVE-2017-5882Cross-site scripting (XSS) vulnerability in index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrar...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now