CVEs from 2017
Total
11,679
critical
critical 1,647
high
high 5,041
medium
medium 4,168
low
low 159
% Critical
14.1%
% with KEV
0.7%
% with exploit
9.8%
Top vendors
Top products
- imagemagick 1,426
- joomla\! 932
- kanboard 848
- ntp 762
- tomcat 676
- mahara 572
- postgresql 492
- asterisk 435
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-14608 | critical | 9.1 | 9.1 | 9y ago | In LibRaw through 0.18.4, an out of bounds read flaw related to kodak_65000_load_raw has been reported in dcraw/dcraw.c and internal/dcraw_common.cpp. An attacker could possibly exploit this flaw to … | |||
| CVE-2017-12883 | critical | 9.1 | 9.1 | 9y ago | Buffer overflow in the S_grok_bslash_N function in regcomp.c in Perl 5 before 5.24.3-RC1 and 5.26.x before 5.26.1-RC1 allows remote attackers to disclose sensitive information or cause a denial of se… | |||
| CVE-2017-0898 | critical | 9.1 | 9.1 | 9y ago | Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting … | |||
| CVE-2017-12249 | critical | 9.1 | 9.1 | 9y ago | A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to… | |||
| CVE-2017-14230 | critical | 9.1 | 9.1 | 9y ago | In the mboxlist_do_find function in imap/mboxlist.c in Cyrus IMAP before 3.0.4, an off-by-one error in prefix calculation for the LIST command caused use of uninitialized memory, which might allow re… | |||
| CVE-2017-14122 | critical | 9.1 | 9.1 | 9y ago | unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp. | |||
| CVE-2017-10833 | critical | 9.1 | 9.1 | 9y ago | "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows remote attackers to bypass access restriction to view information or modify configurations via unspecified vectors. | |||
| CVE-2017-1383 | critical | 9.1 | 9.1 | 9y ago | IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to exp… | |||
| CVE-2017-11694 | critical | 9.1 | 9.1 | 9y ago | MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded credentials and the ability to communicate direct… | |||
| CVE-2017-11693 | critical | 9.1 | 9.1 | 9y ago | MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate … | |||
| CVE-2017-2277 | critical | 9.1 | 9.1 | 9y ago | WG-C10 v3.0.79 and earlier allows an attacker to bypass access restrictions to obtain or alter information stored in the external storage connected to the product via unspecified vectors. | |||
| CVE-2017-9788 | critical | 9.1 | 9.1 | 9y ago | In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assi… | |||
| CVE-2017-11147 | critical | 9.1 | 9.1 | 9y ago | In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due … | |||
| CVE-2017-6711 | critical | 9.1 | 9.1 | 9y ago | A vulnerability in the Ultra Automation Service (UAS) of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device. The vulne… | |||
| CVE-2017-10917 | critical | 9.1 | 9.1 | 9y ago | Xen through 4.8.x does not validate the port numbers of polled event channel ports, which allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) or possibly o… | |||
| CVE-2017-2782 | critical | 9.1 | 9.1 | 9y ago | An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, l… | |||
| CVE-2017-9097 | critical | 9.1 | 9.1 | 9y ago | In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, a… | |||
| CVE-2017-7337 | critical | 9.1 | 9.1 | 9y ago | An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to interact with unauthorized VDOMs or enumerate other ADOMs via another user's stolen ses… | |||
| CVE-2017-9053 | critical | 9.1 | 9.1 | 9y ago | An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_read_loc_expr_op() is due to a failure to check a pointer for being in bounds (in … | |||
| CVE-2017-8872 | critical | 9.1 | 9.1 | 9y ago | The htmlParseTryOrFinish function in HTMLparser.c in libxml2 2.9.4 allows attackers to cause a denial of service (buffer over-read) or information disclosure. | |||
| CVE-2017-8827 | critical | 9.1 | 9.1 | 9y ago | GeniXCMS Arbitrary User Password Reset Vulnerability | |||
| CVE-2017-7229 | critical | 9.1 | 9.1 | 9y ago | PGP/MIME encrypted messages injected into a Vaultive O365 (before 4.5.21) frontend via IMAP or SMTP have their Content-Type changed from 'Content-Type: multipart/encrypted; protocol="application/pgp-… | |||
| CVE-2017-6520 | critical | 9.1 | 9.1 | 9y ago | The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote attackers to cause a de… | |||
| CVE-2017-6519 | critical | 9.1 | 9.1 | 9y ago | avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a denial of service (tra… | |||
| CVE-2017-3508 | critical | 9.1 | 9.1 | 9y ago | Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration). Supported versions that are affected are 1.0, 1.1, 14.2, 15.1, 15.2,… | |||
| CVE-2017-5648 | critical | 9.1 | 9.1 | 9y ago | Exposure of Resource to Wrong Sphere in Apache Tomcat | |||
| CVE-2017-7357 | critical | 9.1 | 9.1 | 9y ago | Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file. | |||
| CVE-2017-2989 | critical | 9.1 | 9.1 | 9y ago | Adobe Campaign versions Build 8770 and earlier have an input validation bypass that could be exploited to read, write, or delete data from the Campaign database. | |||
| CVE-2017-7226 | critical | 9.1 | 9.1 | 9y ago | The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses… | |||
| CVE-2017-6969 | critical | 9.1 | 9.1 | 9y ago | readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak a… | |||
| CVE-2017-2968 | critical | 9.1 | 9.1 | 9y ago | Adobe Campaign versions 16.4 Build 8724 and earlier have a code injection vulnerability. | |||
| CVE-2017-5152 | critical | 9.1 | 9.1 | 9y ago | An issue was discovered in Advantech WebAccess Version 8.1. By accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access pages unrestricted (AUTHENTICA… | |||
| CVE-2017-5142 | critical | 9.1 | 9.1 | 9y ago | An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user with low privileges is able to open and change the pa… | |||
| CVE-2017-5539 | critical | 9.1 | 9.1 | 10y ago | The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ..\/ to bypass the filter rule. Then, this attacker can exploit t… | |||
| CVE-2017-5545 | critical | 9.1 | 9.1 | 10y ago | The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via App… | |||
| CVE-2017-5209 | critical | 9.1 | 9.1 | 10y ago | The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) vi… | |||
| CVE-2017-14591 | critical | 9.0 | 9.0 | 9y ago | Atlassian Fisheye and Crucible versions less than 4.4.3 and version 4.5.0 are vulnerable to argument injection through filenames in Mercurial repositories, allowing attackers to execute arbitrary cod… | |||
| CVE-2017-10102 | critical | 9.0 | 9.0 | 9y ago | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Diff… | |||
| CVE-2017-4919 | critical | 9.0 | 9.0 | 9y ago | VMware vCenter Server 5.5, 6.0, 6.5 allows vSphere users with certain, limited vSphere privileges to use the VIX API to access Guest Operating Systems without the need to authenticate. | |||
| CVE-2017-5691 | critical | 9.0 | 9.0 | 9y ago | Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows… | |||
| CVE-2017-10915 | critical | 9.0 | 9.0 | 9y ago | The shadow-paging feature in Xen through 4.8.x mismanages page references and consequently introduces a race condition, which allows guest OS users to obtain Xen privileges, aka XSA-219. | |||
| CVE-2017-2292 | critical | 9.0 | 9.0 | 9y ago | Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.sa… | |||
| CVE-2017-5206 | critical | 9.0 | 9.0 | 9y ago | Firejail before 0.9.44.4, when running on a Linux kernel before 4.8, allows context-dependent attackers to bypass a seccomp-based sandbox protection mechanism via the --allow-debuggers argument. | |||
| CVE-2017-0021 | critical | 9.0 | 9.0 | 9y ago | Hyper-V in Microsoft Windows 10 1607 and Windows Server 2016 does not properly validate vSMB packet data, which allows attackers to execute arbitrary code on a target OS, aka "Hyper-V System Data Str… | |||
| CVE-2017-2787 | critical | 9.0 | 9.0 | 9y ago | A buffer overflows exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to a heap based buf… | |||
| CVE-2017-2684 | critical | 9.0 | 9.0 | 9y ago | Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level au… | |||
| CVE-2017-3310 | critical | 9.0 | 9.0 | 10y ago | Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having C… | |||
| CVE-2017-7921 | unknown | — | 2.5 | 3mo ago | Multiple Hikvision products contain an improper authentication vulnerability that could allow a malicious user to escalate privileges on the system and gain access to sensitive information. | |||
| CVE-2017-3066 | unknown | — | 2.5 | 1y ago | Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. | |||
| CVE-2017-1000253 | unknown | — | 2.5 | 2y ago | Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. | |||
| CVE-2017-6884 | unknown | — | 2.5 | 3y ago | Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious… | |||
| CVE-2017-18368 | unknown | — | 2.5 | 3y ago | Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host param… | |||
| CVE-2017-11357 | unknown | — | 2.5 | 3y ago | Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution. | |||
| CVE-2017-5521 | unknown | — | 2.5 | 4y ago | Multiple NETGEAR devices are prone to admin password disclosure via simple crafted requests to the web management server. | |||
| CVE-2017-15944 | unknown | — | 2.5 | 4y ago | Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained. | |||
| CVE-2017-0147 | unknown | — | 2.5 | 4y ago | The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet. | |||
| CVE-2017-12617 | unknown | — | 2.5 | 4y ago | When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the serv… | |||
| CVE-2017-9791 | unknown | — | 2.5 | 4y ago | The Struts 1 plugin in Apache Struts might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage. | |||
| CVE-2017-1000353 | unknown | — | 2.5 | 4y ago | Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenkins CLI, that would… | |||
| CVE-2017-11317 | unknown | — | 2.5 | 4y ago | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code. | |||
| CVE-2017-0148 | unknown | — | 2.5 | 4y ago | The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets. | |||
| CVE-2017-0037 | unknown | — | 2.5 | 4y ago | Microsoft Edge and Internet Explorer have a type confusion vulnerability in mshtml.dll, which allows remote code execution. | |||
| CVE-2017-0213 | unknown | — | 2.5 | 4y ago | Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application. | |||
| CVE-2017-0059 | unknown | — | 2.5 | 4y ago | Microsoft Internet Explorer allow remote attackers to obtain sensitive information from process memory via a crafted web site. | |||
| CVE-2017-0146 | unknown | — | 2.5 | 4y ago | The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution. | |||
| CVE-2017-3881 | unknown | — | 2.5 | 4y ago | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected … | |||
| CVE-2017-6334 | unknown | — | 2.5 | 4y ago | dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands | |||
| CVE-2017-6316 | unknown | — | 2.5 | 4y ago | A vulnerability has been identified in the management interface of Citrix NetScaler SD-WAN Enterprise and Standard Edition and Citrix CloudBridge Virtual WAN Edition that could result in an unauthent… | |||
| CVE-2017-0101 | unknown | — | 2.5 | 4y ago | A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory. | |||
| CVE-2017-6077 | unknown | — | 2.5 | 4y ago | NETGEAR DGN2200 wireless routers contain a vulnerability that allows for remote code execution. | |||
| CVE-2017-8540 | unknown | — | 2.5 | 4y ago | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and… | |||
| CVE-2017-6736 | unknown | — | 2.5 | 4y ago | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. | |||
| CVE-2017-8570 | unknown | — | 2.5 | 4y ago | A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory. | |||
| CVE-2017-8464 | unknown | — | 2.5 | 4y ago | Windows Shell in multiple versions of Microsoft Windows allows local users or remote attackers to execute arbitrary code via a crafted .LNK file | |||
| CVE-2017-0144 | unknown | — | 2.5 | 4y ago | The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. | |||
| CVE-2017-0263 | unknown | — | 2.5 | 4y ago | Microsoft Win32k contains a privilege escalation vulnerability due to the Windows kernel-mode driver failing to properly handle objects in memory. | |||
| CVE-2017-10271 | unknown | — | 2.5 | 4y ago | Oracle Corporation WebLogic Server contains a vulnerability that allows for remote code execution. | |||
| CVE-2017-0145 | unknown | — | 2.5 | 4y ago | The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets. | |||
| CVE-2017-5689 | unknown | — | 2.5 | 4y ago | Intel products contain a vulnerability which can allow attackers to perform privilege escalation. | |||
| CVE-2017-17562 | unknown | — | 2.5 | 5y ago | Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. | |||
| CVE-2017-12149 | unknown | — | 2.5 | 5y ago | The JBoss Application Server, shipped with Red Hat Enterprise Application Platform 5.2, allows an attacker to execute arbitrary code via crafted serialized data. | |||
| CVE-2017-7269 | unknown | — | 2.5 | 5y ago | Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If… | |||
| CVE-2017-9248 | unknown | — | 2.5 | 5y ago | Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey… | |||
| CVE-2017-6327 | unknown | — | 2.5 | 5y ago | Symantec Messaging Gateway contains an unspecified vulnerability which can allow for remote code execution. With the ability to perform remote code execution, an attacker may also desire to perform p… | |||
| CVE-2017-0199 | unknown | — | 2.5 | 5y ago | Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution. | |||
| CVE-2017-11882 | unknown | — | 2.5 | 5y ago | Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. | |||
| CVE-2017-8759 | unknown | — | 2.5 | 5y ago | Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system. | |||
| CVE-2017-0143 | unknown | — | 2.5 | 5y ago | Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution. | |||
| CVE-2017-1000486 | unknown | — | 2.5 | 5y ago | Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution | |||
| CVE-2017-5638 | unknown | — | 2.5 | 8y ago | Apache Struts Jakarta Multipart parser allows for malicious file upload using the Content-Type value, leading to remote code execution. | |||
| CVE-2017-12615 | unknown | — | 2.5 | 8y ago | When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it conta… | |||
| CVE-2017-9805 | unknown | — | 2.5 | 8y ago | Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads. | |||
| CVE-2017-9822 | unknown | — | 2.5 | 8y ago | DotNetNuke (DNN) contains a vulnerability that may allow for remote code execution via cookie deserialization. | |||
| CVE-2017-12637 | unknown | — | 1.5 | 1y ago | SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files vi… | |||
| CVE-2017-3506 | unknown | — | 1.5 | 2y ago | Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP req… | |||
| CVE-2017-6742 | unknown | — | 1.5 | 3y ago | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected sys… | |||
| CVE-2017-6862 | unknown | — | 1.5 | 4y ago | Multiple NETGEAR devices contain a buffer overflow vulnerability that allows for authentication bypass and remote code execution. | |||
| CVE-2017-0210 | unknown | — | 1.5 | 4y ago | A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information. | |||
| CVE-2017-0005 | unknown | — | 1.5 | 4y ago | The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application. | |||
| CVE-2017-8543 | unknown | — | 1.5 | 4y ago | Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory. |