2017 CVE Vulnerabilities
17,104 CVEs published in 2017.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2017-20240 | MEDIUM | 5.9 | 0.3% | Jun 12, 2026 | Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks. These versions use Perl's built-in eq... |
| CVE-2017-20239 | MEDIUM | 6.1 | 0.3% | Apr 12, 2026 | MDwiki contains a cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript by inj... |
| CVE-2017-20233 | MEDIUM | 5.4 | 0.2% | Apr 3, 2026 | Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correc... |
| CVE-2017-20219 | MEDIUM | 6.1 | 0.2% | Mar 16, 2026 | Serviio PRO 1.8 DLNA Media Streaming Server contains a DOM-based cross-site scripting vulnerability that allows attacker... |
| CVE-2017-20209 | MEDIUM | 6.1 | 0.5% | Oct 30, 2025 | Nagios Fusion versions prior to 4.0.1 are vulnerable to cross-site scripting (XSS) via the Users and Servers pages. Insu... |
| CVE-2017-20199 | MEDIUM | 6.5 | 0.4% | Aug 16, 2025 | A vulnerability was found in Buttercup buttercup-browser-extension up to 0.14.2. Affected by this vulnerability is an un... |
| CVE-2017-13318 | MEDIUM | 5.7 | 0.1% | Jan 28, 2025 | In HeifDataSource::readAt of HeifDecoderImpl.cpp, there is a possible out of bounds read due to an integer overflow. Thi... |
| CVE-2017-13317 | MEDIUM | 5.7 | 0.1% | Jan 28, 2025 | In HeifDecoderImpl::getScanline of HeifDecoderImpl.cpp, there is a possible out of bounds read due to improper input val... |
| CVE-2017-20196 | MEDIUM | 6.3 | 0.4% | Jan 26, 2025 | A vulnerability was found in Itechscripts School Management Software 2.75. It has been classified as critical. This affe... |
| CVE-2017-13322 | MEDIUM | 5.5 | 0.2% | Jan 17, 2025 | In endCallForSubscriber of PhoneInterfaceManager.java, there is a possible way to prevent access to emergency services d... |
| CVE-2017-13308 | MEDIUM | 6.7 | 0.1% | Dec 5, 2024 | In tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to i... |
| CVE-2017-13321 | MEDIUM | 5.5 | 0.1% | Nov 27, 2024 | In SensorService::isDataInjectionEnabled of frameworks/native/services/sensorservice/SensorService.cpp, there is a possi... |
| CVE-2017-13320 | MEDIUM | 6.5 | 0.2% | Nov 27, 2024 | In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead... |
| CVE-2017-18307 | MEDIUM | 5.5 | 0.1% | Nov 26, 2024 | Information disclosure possible while audio playback. |
| CVE-2017-18306 | MEDIUM | 5.5 | 0.1% | Nov 26, 2024 | Information disclosure due to uninitialized variable. |
| CVE-2017-13313 | MEDIUM | 6.5 | 0.2% | Nov 15, 2024 | In ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of ESQueue.cpp, there is a possible infinite loop leading to resou... |
| CVE-2017-13311 | MEDIUM | 6.7 | 0.1% | Nov 15, 2024 | In the read() function of ProcessStats.java, there is a possible read/write serialization issue leading to a permissions... |
| CVE-2017-13309 | MEDIUM | 5.5 | 0.1% | Nov 15, 2024 | In readEncryptedData of ConscryptEngine.java, there is a possible plaintext leak due to improperly used crypto. This cou... |
| CVE-2017-13227 | MEDIUM | 5.5 | 0.1% | Nov 14, 2024 | In the autofill service, the package name that is provided by the app process is trusted inappropriately. This could le... |
| CVE-2017-20195 | MEDIUM | 5.5 | 0.3% | Oct 29, 2024 | A vulnerability was found in LUNAD3v AreaLoad up to 1a1103182ed63a06dde63d1712f3262eda19c3ec. It has been rated as criti... |
| CVE-2017-20194 | MEDIUM | 5.3 | 1.1% | Oct 16, 2024 | The Formidable Form Builder plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and includi... |
| CVE-2017-20193 | MEDIUM | 6.1 | 0.4% | Oct 16, 2024 | The Product Vendors is vulnerable to Reflected Cross-Site Scripting via the 'vendor_description' parameter in versions u... |
| CVE-2017-20192 | MEDIUM | 6.1 | 1.0% | Oct 16, 2024 | The Formidable Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters su... |
| CVE-2017-3772 | MEDIUM | 5.5 | 0.1% | Jul 31, 2024 | A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a ... |
| CVE-2017-20188 | MEDIUM | 4.7 | 0.4% | Jan 2, 2024 | A vulnerability has been found in Zimbra zm-ajax up to 8.8.1 and classified as problematic. Affected by this vulnerabili... |
Check if your code is affected by 2017 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now