2017 CVE Vulnerabilities

17,104 CVEs published in 2017.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2017-17751Bose SoundTouch devices allows remote attackers to achieve remote control via a crafted web site that uses the WebSocket...
CVE-2017-17750Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify.
CVE-2017-17749Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora.
CVE-2017-18247The av_audio_fifo_size function in libavutil/audio_fifo.c in Libav 12.2 allows remote attackers to cause a denial of ser...
CVE-2017-18246The pcm_encode_frame function in libavcodec/pcm.c in Libav 12.2 allows remote attackers to cause a denial of service (he...
CVE-2017-18245The mpc8_probe function in libavformat/mpc8.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-b...
CVE-2017-15326DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability. DBS3900 TDD LTE suppor...
CVE-2017-15325The Bdat driver of Prague smart phones with software versions earlier than Prague-AL00AC00B211, versions earlier than Pr...
CVE-2017-17736Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visit...
CVE-2017-18244The stereo_processing function in libavcodec/aacps.c in Libav 12.2 allows remote attackers to cause a denial of service ...
CVE-2017-18243The unpack_parse_unit function in libavcodec/dirac_parser.c in Libav 12.2 allows remote attackers to cause a denial of s...
CVE-2017-18242The apply_dependent_coupling function in libavcodec/aacdec.c in Libav 12.2 allows remote attackers to cause a denial of ...
CVE-2017-16242An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authenticati...
CVE-2017-0920GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass iss...
CVE-2017-16772Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and ...
CVE-2017-16771Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 a...
CVE-2017-0934Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the l...
CVE-2017-0933Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attac...
CVE-2017-0932Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the...
CVE-2017-18094Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow r...
CVE-2017-17743Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.2...
CVE-2017-0927Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component ...
CVE-2017-0926Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component re...
CVE-2017-0925Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project se...
CVE-2017-0924Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in p...

Check if your code is affected by 2017 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now