CVEs from 2017

11,679 normalized CVEs published or assigned in this year.

Total
11,679
critical
critical 1,647
high
high 5,041
medium
medium 4,168
low
low 159
% Critical
14.1%
% with KEV
0.7%
% with exploit
9.8%

Top vendors

Top products

  • imagemagick 1,426
  • joomla\! 932
  • kanboard 848
  • ntp 762
  • tomcat 676
  • mahara 572
  • postgresql 492
  • asterisk 435
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-18174 unknown In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free.
CVE-2017-18169 unknown User process can perform the kernel DOS in ashmem when doing cache maintenance operation in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.
CVE-2017-9104 unknown An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.
CVE-2017-18200 unknown The f2fs implementation in the Linux kernel before 4.14 mishandles reference counts associated with f2fs_wait_discard_bios calls, which allows local users to cause a denial of service (BUG), as demon…
CVE-2017-18079 unknown drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact becau…
CVE-2017-18075 unknown crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_…
CVE-2017-18017 unknown The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memor…
CVE-2017-16914 unknown The "stub_send_ret_submit()" function (drivers/usb/usbip/stub_tx.c) in the Linux Kernel before version 4.14.8, 4.9.71, 4.1.49, and 4.4.107 allows attackers to cause a denial of service (NULL pointer …
CVE-2017-16913 unknown The "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 when handling CMD_SUBMIT packets allows attackers to cause a denial …
CVE-2017-9103 unknown An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the first label length. De…
CVE-2017-16912 unknown The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 allows attackers to cause a denial of service (out-of-bounds read) via a special…
CVE-2017-16911 unknown The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is atta…
CVE-2017-15129 unknown A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::…
CVE-2017-15128 unknown A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG).
CVE-2017-15126 unknown A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of fork failure when dealing with event messages. Failure to fork correctly…
CVE-2017-15127 unknown A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local den…
CVE-2017-13305 unknown A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974.
CVE-2017-13215 unknown A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel.
CVE-2017-13220 unknown An elevation of privilege vulnerability in the Upstream kernel bluez. Product: Android. Versions: Android kernel. Android ID: A-63527053.
CVE-2017-14178 unknown In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's acce…
CVE-2017-2661 unknown ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster.
CVE-2017-7482 unknown In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the …
CVE-2017-7558 unknown A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13…
CVE-2017-7518 unknown A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug except…
CVE-2017-15108 unknown spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary comm…
CVE-2017-12150 unknown It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-…
CVE-2017-20189 unknown 2y ago Clojure classes can be used to craft a serialized object that runs arbitrary code on deserialization
CVE-2017-20151 unknown 4y ago iText RUPS XML External Entity vulnerability
CVE-2017-15683 unknown 4y ago XML injection in Crafter CMS
CVE-2017-15682 unknown 4y ago Cross site scripting in Crafter CMS
CVE-2017-15680 unknown 4y ago Missing Authorization in Crafter CMS
CVE-2017-11365 unknown 4y ago Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The compo…
CVE-2017-12622 unknown 4y ago Apache Geode gfsh authorization vulnerability
CVE-2017-9796 unknown 4y ago Apache Geode OQL bind parameter vulnerability
CVE-2017-15717 unknown 4y ago Cross-site Scripting in Apache Sling XSS Protection API
CVE-2017-3158 unknown 4y ago Apache Guacamole Race Condition vulnerability
CVE-2017-1000397 unknown 4y ago MitM on Jenkins Maven Plugin
CVE-2017-1000402 unknown 4y ago Jenkins Swarm Plugin Client vulnerable to man-in-the-middle attacks
CVE-2017-1000404 unknown 4y ago Jenkins Delivery Pipeline Plugin Cross-site Scripting vulnerability
CVE-2017-1000505 unknown 4y ago Exposure of Sensitive Information to an Unauthorized Actor Jenkins Script Security Plugin
CVE-2017-1000389 unknown 4y ago Cross-Site Request Forgery (CSRF) vulnerability in Jenkins global-build-stats plugin
CVE-2017-1000503 unknown 4y ago Race Condition in Jenkins
CVE-2017-15697 unknown 4y ago Apache NiFi XSS issue in context path handling
CVE-2017-1000502 unknown 4y ago Arbitrary shell command execution in Jenkins EC2 Plugin
CVE-2017-12632 unknown 4y ago Apache NiFi host header poisoning issue
CVE-2017-15712 unknown 4y ago Path Traversal in Apache Oozie
CVE-2017-15696 unknown 4y ago Apache Geode configuration request authorization vulnerability
CVE-2017-15693 unknown 4y ago Apache Geode unsafe deserialization of application objects
CVE-2017-15692 unknown 4y ago Apache Geode unsafe deserialization in TcpServer
CVE-2017-1000425 unknown 4y ago Liferay Portal XSS vulnerability via movie parameter in the /html/portal/flash.jsp page
CVE-2017-16790 unknown 4y ago An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST …
CVE-2017-16652 unknown 4y ago An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler t…
CVE-2017-16654 unknown 4y ago An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the …
CVE-2017-15706 unknown 4y ago Inconsistent documentation in Apache Tomcat
CVE-2017-1000504 unknown 4y ago Cross-Site Request Forgery in Jenkins
CVE-2017-1000399 unknown 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
CVE-2017-1000395 unknown 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
CVE-2017-1000401 unknown 4y ago Improper Input Validation in Jenkins
CVE-2017-1000396 unknown 4y ago Improper Certificate Validation in Jenkins
CVE-2017-1000398 unknown 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
CVE-2017-1000394 unknown 4y ago Improper Input Validation in Jenkins
CVE-2017-1000393 unknown 4y ago OS Command Injection in Jenkins
CVE-2017-1000391 unknown 4y ago Improper Input Validation in Jenkins
CVE-2017-1000392 unknown 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2017-15089 unknown 4y ago Deserialization of Untrusted Data in Infinispan
CVE-2017-1000386 unknown 4y ago Cross-site Scripting in Jenkins Active Choices plugin
CVE-2017-15719 unknown 4y ago Cross-site Scripting in wicket-jquery-ui
CVE-2017-15691 unknown 4y ago Improper Restriction of XML External Entity Reference in Apache uimaj
CVE-2017-9795 unknown 4y ago Apache Geode OQL method invocation vulnerability
CVE-2017-1000190 unknown 4y ago SimpleXML has XML External Entity (XXE) vulnerability
CVE-2017-18191 unknown 4y ago An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt t…
CVE-2017-16653 unknown 4y ago An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different token…
CVE-2017-1000387 unknown 4y ago Jenkins Build-Publisher plugin has Insufficiently Protected Credentials
CVE-2017-1000403 unknown 4y ago Arbitrary code execution vulnerability in Jenkins Speaks! Plugin
CVE-2017-12165 unknown 4y ago Undertow Request Smuggling vulnerability
CVE-2017-12196 unknown 4y ago Incorrect Authorization in Undertow
CVE-2017-12197 unknown 4y ago Improper Input Validation in libpam4j
CVE-2017-2598 unknown 4y ago Inadequate Encryption Strength in Jenkins
CVE-2017-2602 unknown 4y ago Incomplete List of Disallowed Inputs in Jenkins
CVE-2017-2600 unknown 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
CVE-2017-2589 unknown 4y ago Insecure cookie sharing in Hawtio
CVE-2017-2594 unknown 4y ago Path Traversal in io.hawt:project
CVE-2017-2607 unknown 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2017-2604 unknown 4y ago Improper Authentication in Jenkins
CVE-2017-2609 unknown 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
CVE-2017-2608 unknown 4y ago Deserialization of Untrusted Data in Jenkins
CVE-2017-2610 unknown 4y ago Improper Neutralization of Input During Web Page Generation in Jenkins
CVE-2017-2612 unknown 4y ago Incorrect Permission Assignment for Critical Resource in Jenkins
CVE-2017-2613 unknown 4y ago Cross-Site Request Forgery in Jenkins
CVE-2017-2603 unknown 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
CVE-2017-2606 unknown 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
CVE-2017-2638 unknown 4y ago Infinispan Rest API Does Not Enforce Auth Constraints
CVE-2017-2649 unknown 4y ago Jenkins Active Directory Plugin did not verify certificate of AD server
CVE-2017-2648 unknown 4y ago Jenkins SSH Build Agents Plugin did not verify host keys
CVE-2017-2651 unknown 4y ago Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
CVE-2017-2654 unknown 4y ago Emails were sent to addresses not associated with actual users of Jenkins by Email Extension Plugin
CVE-2017-2650 unknown 4y ago Jenkins Pipeline Classpath Step plugin allowed Script Security sandbox bypass
CVE-2017-2652 unknown 4y ago Missing permission checks in Jenkins Distributed Fork Plugin
CVE-2017-3203 unknown 4y ago Deserialization of Untrusted Data in Spring-flex
CVE-2017-3202 unknown 4y ago Deserialization of Untrusted Data in Flamingo amf-serializer