CVEs from 2017

11,679 normalized CVEs published or assigned in this year.

Total
11,679
critical
critical 1,647
high
high 5,041
medium
medium 4,168
low
low 159
% Critical
14.1%
% with KEV
0.7%
% with exploit
9.8%

Top vendors

Top products

  • imagemagick 1,426
  • joomla\! 932
  • kanboard 848
  • ntp 762
  • tomcat 676
  • mahara 572
  • postgresql 492
  • asterisk 435
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-15409 critical 9.5 multiple issues in chromium
CVE-2017-7779 critical 9.5 multiple issues in thunderbird
CVE-2017-7786 critical 9.5 multiple issues in thunderbird
CVE-2017-5412 critical 9.5 A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird < 52.
CVE-2017-5390 critical 9.5 multiple issues in thunderbird
CVE-2017-7835 critical 9.5 Mixed content blocking of insecure (HTTP) sub-resources in a secure (HTTPS) document was not correctly applied for resources that redirect from HTTPS to HTTP, allowing content that should be blocked,…
CVE-2017-5408 critical 9.5 multiple issues in thunderbird
CVE-2017-7750 critical 9.5 multiple issues in thunderbird
CVE-2017-5407 critical 9.5 multiple issues in thunderbird
CVE-2017-7832 critical 9.5 The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the addressbar by the dotless version of 'i' followed…
CVE-2017-5399 critical 9.5 Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary c…
CVE-2017-5441 critical 9.5 A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firef…
CVE-2017-7794 critical 9.5 On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no wr…
CVE-2017-7778 critical 9.5 multiple issues in thunderbird
CVE-2017-5442 critical 9.5 A use-after-free vulnerability during changes in style when manipulating DOM elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45…
CVE-2017-15422 critical 9.5 multiple issues in chromium
CVE-2017-5410 critical 9.5 multiple issues in thunderbird
CVE-2017-7749 critical 9.5 multiple issues in thunderbird
CVE-2017-5469 critical 9.5 Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5443 critical 9.5 An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5126 critical 9.5 multiple issues in chromium
CVE-2017-5433 critical 9.5 A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a poten…
CVE-2017-5464 critical 9.5 During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. T…
CVE-2017-5460 critical 9.5 A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability…
CVE-2017-5389 critical 9.5 WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. Thi…
CVE-2017-5420 critical 9.5 A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious pag…
CVE-2017-7752 critical 9.5 multiple issues in thunderbird
CVE-2017-5374 critical 9.5 Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary…
CVE-2017-5468 critical 9.5 An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash when manually triggered during debugging. This vul…
CVE-2017-7776 critical 9.5 multiple issues in thunderbird
CVE-2017-15423 critical 9.5 multiple issues in chromium
CVE-2017-5459 critical 9.5 A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox…
CVE-2017-7839 critical 9.5 Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This …
CVE-2017-7758 critical 9.5 multiple issues in thunderbird
CVE-2017-7754 critical 9.5 multiple issues in thunderbird
CVE-2017-5396 critical 9.5 multiple issues in thunderbird
CVE-2017-7774 critical 9.5 multiple issues in thunderbird
CVE-2017-5426 critical 9.5 On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox …
CVE-2017-7764 critical 9.5 multiple issues in thunderbird
CVE-2017-7823 critical 9.5 multiple issues in thunderbird
CVE-2017-5417 critical 9.5 When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the addressbar so that the displayed location following navigation does not match t…
CVE-2017-12375 critical 9.5 The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device…
CVE-2017-15389 critical 9.5 multiple issues in chromium
CVE-2017-7000 critical 9.5 multiple issues in chromium
CVE-2017-5383 critical 9.5 multiple issues in thunderbird
CVE-2017-7791 critical 9.5 multiple issues in thunderbird
CVE-2017-5419 critical 9.5 If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-responsive, requiring shutdown through the operating system. This is a denial of servi…
CVE-2017-15396 critical 9.5 arbitrary code execution in chromium
CVE-2017-5379 critical 9.5 Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulnerability affects Firefox < 51.
CVE-2017-5472 critical 9.5 multiple issues in thunderbird
CVE-2017-5444 critical 9.5 A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from mem…
CVE-2017-5405 critical 9.5 multiple issues in thunderbird
CVE-2017-12380 critical 9.5 ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. Th…
CVE-2017-5125 critical 9.5 multiple issues in chromium
CVE-2017-7757 critical 9.5 multiple issues in thunderbird
CVE-2017-15394 critical 9.5 multiple issues in chromium
CVE-2017-7838 critical 9.5 Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode display instead of the primary domain being displayed …
CVE-2017-12374 critical 9.5 The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device…
CVE-2017-7818 critical 9.5 multiple issues in thunderbird
CVE-2017-5376 critical 9.5 multiple issues in thunderbird
CVE-2017-7793 critical 9.5 multiple issues in thunderbird
CVE-2017-15417 critical 9.5 multiple issues in chromium
CVE-2017-7775 critical 9.5 multiple issues in thunderbird
CVE-2017-5416 critical 9.5 In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vulnerability affects Firefox < 52 and Thunderbird < 5…
CVE-2017-15412 critical 9.5 9y ago multiple issues in chromium
CVE-2017-3558 high 8.5 9.5 9y ago Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" v…
CVE-2017-14000 critical 9.4 9.4 9y ago An Improper Authentication issue was discovered in Ctek SkyRouter Series 4200 and 4400, all versions prior to V6.00.11. By accessing a specific uniform resource locator (URL) on the web server, a mal…
CVE-2017-9630 critical 9.4 9.4 9y ago An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpr…
CVE-2017-3587 high 8.4 9.4 9y ago Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Shared Folder). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "explo…
CVE-2017-6970 high 8.4 9.4 9y ago AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privileged context via an NfSen socket, aka AlienVault ID ENG-104863.
CVE-2017-3316 high 8.4 9.4 10y ago Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are VirtualBox prior to 5.0.32 and prior to 5.1.14. Easily explo…
CVE-2017-11322 high 8.2 9.2 9y ago The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileges via a dollar sign ($) metacharacter in the argument to chroothole_client.
CVE-2017-10246 high 8.2 9.2 9y ago Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: iHelp). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. …
CVE-2017-7228 high 8.2 9.2 9y ago An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The earlier XSA-29 fix introduced an insufficient check on XENMEM_exchange input, al…
CVE-2017-16727 critical 9.1 9.1 9y ago A Credentials Management issue was discovered in Moxa NPort W2150A versions prior to 1.11, and NPort W2250A versions prior to 1.11. The default password is empty on the device. An unauthorized user c…
CVE-2017-15524 critical 9.1 9.1 9y ago The Application Firewall Pack (AFP, aka Web Application Firewall) component on Kemp Load Balancer devices with software before 7.2.40.1 allows a Security Feature Bypass via an HTTP POST request.
CVE-2017-14090 critical 9.1 9.1 9y ago A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.
CVE-2017-14590 critical 9.1 9.1 9y ago Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has…
CVE-2017-15896 critical 9.1 9.1 9y ago Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could send application dat…
CVE-2017-13150 critical 9.1 9.1 9y ago An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-38328132.
CVE-2017-13149 critical 9.1 9.1 9y ago An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65719872.
CVE-2017-0879 critical 9.1 9.1 9y ago An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-65025028.
CVE-2017-16929 high 8.1 9.1 9y ago The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversal vulnerability exploited by issuing a specially crafted request, allowing a re…
CVE-2017-14487 critical 9.1 9.1 9y ago The OhMiBod Remote app for Android and iOS allows remote attackers to impersonate users by sniffing network traffic for search responses from the OhMiBod API server and then editing the username, use…
CVE-2017-10861 critical 9.1 9.1 9y ago Directory traversal vulnerability in QND Advance/Standard allows an attacker to read arbitrary files via a specially crafted command.
CVE-2017-13872 high 8.1 9.1 9y ago An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The issue involves the "Directory Utility" component. It allows attackers to obtain a…
CVE-2017-0854 critical 9.1 9.1 9y ago An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63873837.
CVE-2017-0853 critical 9.1 9.1 9y ago An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63121644.
CVE-2017-5738 critical 9.1 9.1 9y ago Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 allows an attacker with network access to cause a denial of service and/or inform…
CVE-2017-8807 critical 9.1 9.1 9y ago vbf_stp_error in bin/varnishd/cache/cache_fetch.c in Varnish HTTP Cache 4.1.x before 4.1.9 and 5.x before 5.2.1 allows remote attackers to obtain sensitive information from process memory because a V…
CVE-2017-15806 high 8.1 9.1 9y ago Zeta Components Mail Arbitrary code execution via a crafted email address
CVE-2017-15535 critical 9.1 9.1 9y ago MongoDB 3.4.x before 3.4.10, and 3.5.x-development, has a disabled-by-default configuration setting, networkMessageCompressors (aka wire protocol compression), which exposes a vulnerability when enab…
CVE-2017-1000257 critical 9.1 9.1 9y ago An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer …
CVE-2017-15597 critical 9.1 9.1 9y ago An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page reference. Other portions of code, however, did not mat…
CVE-2017-7115 high 8.1 9.1 9y ago An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue involves the "Wi-Fi" component. It might allow remote attackers to execute arbitrar…
CVE-2017-10330 critical 9.1 9.1 9y ago Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Gantt Server). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and …
CVE-2017-10329 critical 9.1 9.1 9y ago Vulnerability in the Oracle Global Order Promising component of Oracle E-Business Suite (subcomponent: Reschedule Sales Orders). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.…
CVE-2017-8805 critical 9.1 9.1 9y ago Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror.
CVE-2017-14084 high 8.1 9.1 9y ago A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to execute arbitrary code on vulnerable installations.
CVE-2017-7544 critical 9.1 9.1 9y ago libexif through 0.6.21 is vulnerable to out-of-bounds heap read vulnerability in exif_data_save_data_entry function in libexif/exif-data.c caused by improper length computation of the allocated data …