2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-17751 | — | — | 1.0% | Mar 24, 2018 | Bose SoundTouch devices allows remote attackers to achieve remote control via a crafted web site that uses the WebSocket... |
| CVE-2017-17750 | — | — | 0.5% | Mar 24, 2018 | Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify. |
| CVE-2017-17749 | — | — | 0.5% | Mar 24, 2018 | Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora. |
| CVE-2017-18247 | — | — | 1.0% | Mar 23, 2018 | The av_audio_fifo_size function in libavutil/audio_fifo.c in Libav 12.2 allows remote attackers to cause a denial of ser... |
| CVE-2017-18246 | — | — | 1.0% | Mar 23, 2018 | The pcm_encode_frame function in libavcodec/pcm.c in Libav 12.2 allows remote attackers to cause a denial of service (he... |
| CVE-2017-18245 | — | — | 1.4% | Mar 23, 2018 | The mpc8_probe function in libavformat/mpc8.c in Libav 12.2 allows remote attackers to cause a denial of service (heap-b... |
| CVE-2017-15326 | — | — | 0.4% | Mar 23, 2018 | DBS3900 TDD LTE V100R003C00, V100R004C10 have a weak encryption algorithm security vulnerability. DBS3900 TDD LTE suppor... |
| CVE-2017-15325 | — | — | 1.0% | Mar 23, 2018 | The Bdat driver of Prague smart phones with software versions earlier than Prague-AL00AC00B211, versions earlier than Pr... |
| CVE-2017-17736 | — | — | 69.4% | Mar 23, 2018 | Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visit... |
| CVE-2017-18244 | — | — | 1.0% | Mar 22, 2018 | The stereo_processing function in libavcodec/aacps.c in Libav 12.2 allows remote attackers to cause a denial of service ... |
| CVE-2017-18243 | — | — | 1.0% | Mar 22, 2018 | The unpack_parse_unit function in libavcodec/dirac_parser.c in Libav 12.2 allows remote attackers to cause a denial of s... |
| CVE-2017-18242 | — | — | 1.2% | Mar 22, 2018 | The apply_dependent_coupling function in libavcodec/aacdec.c in Libav 12.2 allows remote attackers to cause a denial of ... |
| CVE-2017-16242 | — | — | 0.5% | Mar 22, 2018 | An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authenticati... |
| CVE-2017-0920 | — | — | 0.9% | Mar 22, 2018 | GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass iss... |
| CVE-2017-16772 | — | — | 3.2% | Mar 22, 2018 | Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and ... |
| CVE-2017-16771 | — | — | 1.3% | Mar 22, 2018 | Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 a... |
| CVE-2017-0934 | — | — | 1.3% | Mar 22, 2018 | Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from an Improper Privilege Management vulnerability due to the l... |
| CVE-2017-0933 | — | — | 0.6% | Mar 22, 2018 | Ubiquiti Networks EdgeOS version 1.9.1 and prior suffer from a Cross-Site Request Forgery (CSRF) vulnerability. An attac... |
| CVE-2017-0932 | — | — | 1.3% | Mar 22, 2018 | Ubiquiti Networks EdgeOS version 1.9.1.1 and prior suffer from an Improper Privilege Management vulnerability due to the... |
| CVE-2017-18094 | — | — | 0.6% | Mar 22, 2018 | Various resources in Atlassian Fisheye and Crucible before version 4.4.3 (the fixed version for 4.4.x) and 4.5.0 allow r... |
| CVE-2017-17743 | — | — | 1.1% | Mar 22, 2018 | Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices before 4.4.2... |
| CVE-2017-0927 | — | — | 0.8% | Mar 21, 2018 | Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component ... |
| CVE-2017-0926 | — | — | 1.5% | Mar 21, 2018 | Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component re... |
| CVE-2017-0925 | — | — | 0.9% | Mar 21, 2018 | Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project se... |
| CVE-2017-0924 | — | — | 0.8% | Mar 21, 2018 | Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in p... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now