2017 CVE Vulnerabilities
17,105 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-0408 | — | — | 1.2% | Feb 8, 2017 | A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbit... |
| CVE-2017-0407 | — | — | 1.9% | Feb 8, 2017 | A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause me... |
| CVE-2017-0406 | — | — | 1.9% | Feb 8, 2017 | A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause me... |
| CVE-2017-0405 | — | — | 1.8% | Feb 8, 2017 | A remote code execution vulnerability in Surfaceflinger could enable an attacker using a specially crafted file to cause... |
| CVE-2017-5677 | — | — | 4.8% | Feb 6, 2017 | PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code... |
| CVE-2017-5595 | — | — | 0.4% | Feb 6, 2017 | A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of ... |
| CVE-2017-5368 | — | — | 1.1% | Feb 6, 2017 | ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forger... |
| CVE-2017-5367 | — | — | 2.0% | Feb 6, 2017 | Multiple reflected XSS vulnerabilities exist within form and link input parameters of ZoneMinder v1.30 and v1.29, an ope... |
| CVE-2017-5879 | — | — | 1.9% | Feb 6, 2017 | An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated u... |
| CVE-2017-5877 | — | — | 0.9% | Feb 6, 2017 | XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction param... |
| CVE-2017-5876 | — | — | 0.9% | Feb 6, 2017 | XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter. |
| CVE-2017-5875 | — | — | 0.6% | Feb 6, 2017 | XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter. |
| CVE-2017-5577 | — | — | 0.4% | Feb 6, 2017 | The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 d... |
| CVE-2017-5576 | HIGH | 7.8 | 0.4% | Feb 6, 2017 | Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux k... |
| CVE-2017-5551 | — | — | 0.4% | Feb 6, 2017 | The simple_set_acl function in fs/posix_acl.c in the Linux kernel before 4.9.6 preserves the setgid bit during a setxatt... |
| CVE-2017-5550 | — | — | 0.4% | Feb 6, 2017 | Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to o... |
| CVE-2017-5549 | — | — | 0.4% | Feb 6, 2017 | The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitia... |
| CVE-2017-5548 | — | — | 0.5% | Feb 6, 2017 | drivers/net/ieee802154/atusb.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK o... |
| CVE-2017-5547 | HIGH | 7.8 | 0.4% | Feb 6, 2017 | drivers/hid/hid-corsair.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option... |
| CVE-2017-5546 | HIGH | 7.8 | 0.4% | Feb 6, 2017 | The freelist-randomization feature in mm/slab.c in the Linux kernel 4.8.x and 4.9.x before 4.9.5 allows local users to c... |
| CVE-2017-2596 | — | — | 0.4% | Feb 6, 2017 | The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXO... |
| CVE-2017-2583 | — | — | 0.6% | Feb 6, 2017 | The load_segment_descriptor implementation in arch/x86/kvm/emulate.c in the Linux kernel before 4.9.5 improperly emulate... |
| CVE-2017-5137 | — | — | 1.0% | Feb 5, 2017 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the S... |
| CVE-2017-5136 | — | — | 1.8% | Feb 5, 2017 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. The application failed to check the access c... |
| CVE-2017-5882 | — | — | 0.8% | Feb 4, 2017 | Cross-site scripting (XSS) vulnerability in index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrar... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now