CVEs from 2017
Total
11,679
critical
critical 1,647
high
high 5,041
medium
medium 4,168
low
low 159
% Critical
14.1%
% with KEV
0.7%
% with exploit
9.8%
Top vendors
Top products
- imagemagick 1,426
- joomla\! 932
- kanboard 848
- ntp 762
- tomcat 676
- mahara 572
- postgresql 492
- asterisk 435
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18174 | unknown | — | — | — | In the Linux kernel before 4.7, the amd_gpio_remove function in drivers/pinctrl/pinctrl-amd.c calls the pinctrl_unregister function, leading to a double free. | |||
| CVE-2017-18169 | unknown | — | — | — | User process can perform the kernel DOS in ashmem when doing cache maintenance operation in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel. | |||
| CVE-2017-9104 | unknown | — | — | — | An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered. | |||
| CVE-2017-18200 | unknown | — | — | — | The f2fs implementation in the Linux kernel before 4.14 mishandles reference counts associated with f2fs_wait_discard_bios calls, which allows local users to cause a denial of service (BUG), as demon… | |||
| CVE-2017-18079 | unknown | — | — | — | drivers/input/serio/i8042.c in the Linux kernel before 4.12.4 allows attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact becau… | |||
| CVE-2017-18075 | unknown | — | — | — | crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_… | |||
| CVE-2017-18017 | unknown | — | — | — | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memor… | |||
| CVE-2017-16914 | unknown | — | — | — | The "stub_send_ret_submit()" function (drivers/usb/usbip/stub_tx.c) in the Linux Kernel before version 4.14.8, 4.9.71, 4.1.49, and 4.4.107 allows attackers to cause a denial of service (NULL pointer … | |||
| CVE-2017-16913 | unknown | — | — | — | The "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 when handling CMD_SUBMIT packets allows attackers to cause a denial … | |||
| CVE-2017-9103 | unknown | — | — | — | An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the first label length. De… | |||
| CVE-2017-16912 | unknown | — | — | — | The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) in the Linux Kernel before version 4.14.8, 4.9.71, and 4.4.114 allows attackers to cause a denial of service (out-of-bounds read) via a special… | |||
| CVE-2017-16911 | unknown | — | — | — | The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is atta… | |||
| CVE-2017-15129 | unknown | — | — | — | A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::… | |||
| CVE-2017-15128 | unknown | — | — | — | A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13.12. A lack of size check could cause a denial of service (BUG). | |||
| CVE-2017-15126 | unknown | — | — | — | A use-after-free flaw was found in fs/userfaultfd.c in the Linux kernel before 4.13.6. The issue is related to the handling of fork failure when dealing with event messages. Failure to fork correctly… | |||
| CVE-2017-15127 | unknown | — | — | — | A flaw was found in the hugetlb_mcopy_atomic_pte function in mm/hugetlb.c in the Linux kernel before 4.13. A superfluous implicit page unlock for VM_SHARED hugetlbfs mapping could trigger a local den… | |||
| CVE-2017-13305 | unknown | — | — | — | A information disclosure vulnerability in the Upstream kernel encrypted-keys. Product: Android. Versions: Android kernel. Android ID: A-70526974. | |||
| CVE-2017-13215 | unknown | — | — | — | A elevation of privilege vulnerability in the Upstream kernel skcipher. Product: Android. Versions: Android kernel. Android ID: A-64386293. References: Upstream kernel. | |||
| CVE-2017-13220 | unknown | — | — | — | An elevation of privilege vulnerability in the Upstream kernel bluez. Product: Android. Versions: Android kernel. Android ID: A-63527053. | |||
| CVE-2017-14178 | unknown | — | — | — | In snapd 2.27 through 2.29.2 the 'snap logs' command could be made to call journalctl without match arguments and therefore allow unprivileged, unauthenticated users to bypass systemd-journald's acce… | |||
| CVE-2017-2661 | unknown | — | — | — | ClusterLabs pcs before version 0.9.157 is vulnerable to a cross-site scripting vulnerability due to improper validation of Node name field when creating new cluster or adding existing cluster. | |||
| CVE-2017-7482 | unknown | — | — | — | In the Linux kernel before version 4.12, Kerberos 5 tickets decoded when using the RXRPC keys incorrectly assumes the size of a field. This could lead to the size-remaining variable wrapping and the … | |||
| CVE-2017-7558 | unknown | — | — | — | A kernel data leak due to an out-of-bound read was found in the Linux kernel in inet_diag_msg_sctp{,l}addr_fill() and sctp_get_sctp_info() functions present since version 4.7-rc1 through version 4.13… | |||
| CVE-2017-7518 | unknown | — | — | — | A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug except… | |||
| CVE-2017-15108 | unknown | — | — | — | spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local attacker with access to the session the agent runs in to inject arbitrary comm… | |||
| CVE-2017-12150 | unknown | — | — | — | It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-… | |||
| CVE-2017-20189 | unknown | — | — | 2y ago | Clojure classes can be used to craft a serialized object that runs arbitrary code on deserialization | |||
| CVE-2017-20151 | unknown | — | — | 4y ago | iText RUPS XML External Entity vulnerability | |||
| CVE-2017-15683 | unknown | — | — | 4y ago | XML injection in Crafter CMS | |||
| CVE-2017-15682 | unknown | — | — | 4y ago | Cross site scripting in Crafter CMS | |||
| CVE-2017-15680 | unknown | — | — | 4y ago | Missing Authorization in Crafter CMS | |||
| CVE-2017-11365 | unknown | — | — | 4y ago | Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The compo… | |||
| CVE-2017-12622 | unknown | — | — | 4y ago | Apache Geode gfsh authorization vulnerability | |||
| CVE-2017-9796 | unknown | — | — | 4y ago | Apache Geode OQL bind parameter vulnerability | |||
| CVE-2017-15717 | unknown | — | — | 4y ago | Cross-site Scripting in Apache Sling XSS Protection API | |||
| CVE-2017-3158 | unknown | — | — | 4y ago | Apache Guacamole Race Condition vulnerability | |||
| CVE-2017-1000397 | unknown | — | — | 4y ago | MitM on Jenkins Maven Plugin | |||
| CVE-2017-1000402 | unknown | — | — | 4y ago | Jenkins Swarm Plugin Client vulnerable to man-in-the-middle attacks | |||
| CVE-2017-1000404 | unknown | — | — | 4y ago | Jenkins Delivery Pipeline Plugin Cross-site Scripting vulnerability | |||
| CVE-2017-1000505 | unknown | — | — | 4y ago | Exposure of Sensitive Information to an Unauthorized Actor Jenkins Script Security Plugin | |||
| CVE-2017-1000389 | unknown | — | — | 4y ago | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins global-build-stats plugin | |||
| CVE-2017-1000503 | unknown | — | — | 4y ago | Race Condition in Jenkins | |||
| CVE-2017-15697 | unknown | — | — | 4y ago | Apache NiFi XSS issue in context path handling | |||
| CVE-2017-1000502 | unknown | — | — | 4y ago | Arbitrary shell command execution in Jenkins EC2 Plugin | |||
| CVE-2017-12632 | unknown | — | — | 4y ago | Apache NiFi host header poisoning issue | |||
| CVE-2017-15712 | unknown | — | — | 4y ago | Path Traversal in Apache Oozie | |||
| CVE-2017-15696 | unknown | — | — | 4y ago | Apache Geode configuration request authorization vulnerability | |||
| CVE-2017-15693 | unknown | — | — | 4y ago | Apache Geode unsafe deserialization of application objects | |||
| CVE-2017-15692 | unknown | — | — | 4y ago | Apache Geode unsafe deserialization in TcpServer | |||
| CVE-2017-1000425 | unknown | — | — | 4y ago | Liferay Portal XSS vulnerability via movie parameter in the /html/portal/flash.jsp page | |||
| CVE-2017-16790 | unknown | — | — | 4y ago | An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST … | |||
| CVE-2017-16652 | unknown | — | — | 4y ago | An issue was discovered in Symfony 2.7.x before 2.7.38, 2.8.x before 2.8.31, 3.2.x before 3.2.14, and 3.3.x before 3.3.13. DefaultAuthenticationSuccessHandler or DefaultAuthenticationFailureHandler t… | |||
| CVE-2017-16654 | unknown | — | — | 4y ago | An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the … | |||
| CVE-2017-15706 | unknown | — | — | 4y ago | Inconsistent documentation in Apache Tomcat | |||
| CVE-2017-1000504 | unknown | — | — | 4y ago | Cross-Site Request Forgery in Jenkins | |||
| CVE-2017-1000399 | unknown | — | — | 4y ago | Exposure of Sensitive Information to an Unauthorized Actor in Jenkins | |||
| CVE-2017-1000395 | unknown | — | — | 4y ago | Exposure of Sensitive Information to an Unauthorized Actor in Jenkins | |||
| CVE-2017-1000401 | unknown | — | — | 4y ago | Improper Input Validation in Jenkins | |||
| CVE-2017-1000396 | unknown | — | — | 4y ago | Improper Certificate Validation in Jenkins | |||
| CVE-2017-1000398 | unknown | — | — | 4y ago | Exposure of Sensitive Information to an Unauthorized Actor in Jenkins | |||
| CVE-2017-1000394 | unknown | — | — | 4y ago | Improper Input Validation in Jenkins | |||
| CVE-2017-1000393 | unknown | — | — | 4y ago | OS Command Injection in Jenkins | |||
| CVE-2017-1000391 | unknown | — | — | 4y ago | Improper Input Validation in Jenkins | |||
| CVE-2017-1000392 | unknown | — | — | 4y ago | Improper Neutralization of Input During Web Page Generation in Jenkins | |||
| CVE-2017-15089 | unknown | — | — | 4y ago | Deserialization of Untrusted Data in Infinispan | |||
| CVE-2017-1000386 | unknown | — | — | 4y ago | Cross-site Scripting in Jenkins Active Choices plugin | |||
| CVE-2017-15719 | unknown | — | — | 4y ago | Cross-site Scripting in wicket-jquery-ui | |||
| CVE-2017-15691 | unknown | — | — | 4y ago | Improper Restriction of XML External Entity Reference in Apache uimaj | |||
| CVE-2017-9795 | unknown | — | — | 4y ago | Apache Geode OQL method invocation vulnerability | |||
| CVE-2017-1000190 | unknown | — | — | 4y ago | SimpleXML has XML External Entity (XXE) vulnerability | |||
| CVE-2017-18191 | unknown | — | — | 4y ago | An issue was discovered in OpenStack Nova 15.x through 15.1.0 and 16.x through 16.1.1. By detaching and reattaching an encrypted volume, an attacker may access the underlying raw volume and corrupt t… | |||
| CVE-2017-16653 | unknown | — | — | 4y ago | An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different token… | |||
| CVE-2017-1000387 | unknown | — | — | 4y ago | Jenkins Build-Publisher plugin has Insufficiently Protected Credentials | |||
| CVE-2017-1000403 | unknown | — | — | 4y ago | Arbitrary code execution vulnerability in Jenkins Speaks! Plugin | |||
| CVE-2017-12165 | unknown | — | — | 4y ago | Undertow Request Smuggling vulnerability | |||
| CVE-2017-12196 | unknown | — | — | 4y ago | Incorrect Authorization in Undertow | |||
| CVE-2017-12197 | unknown | — | — | 4y ago | Improper Input Validation in libpam4j | |||
| CVE-2017-2598 | unknown | — | — | 4y ago | Inadequate Encryption Strength in Jenkins | |||
| CVE-2017-2602 | unknown | — | — | 4y ago | Incomplete List of Disallowed Inputs in Jenkins | |||
| CVE-2017-2600 | unknown | — | — | 4y ago | Exposure of Sensitive Information to an Unauthorized Actor in Jenkins | |||
| CVE-2017-2589 | unknown | — | — | 4y ago | Insecure cookie sharing in Hawtio | |||
| CVE-2017-2594 | unknown | — | — | 4y ago | Path Traversal in io.hawt:project | |||
| CVE-2017-2607 | unknown | — | — | 4y ago | Improper Neutralization of Input During Web Page Generation in Jenkins | |||
| CVE-2017-2604 | unknown | — | — | 4y ago | Improper Authentication in Jenkins | |||
| CVE-2017-2609 | unknown | — | — | 4y ago | Exposure of Sensitive Information to an Unauthorized Actor in Jenkins | |||
| CVE-2017-2608 | unknown | — | — | 4y ago | Deserialization of Untrusted Data in Jenkins | |||
| CVE-2017-2610 | unknown | — | — | 4y ago | Improper Neutralization of Input During Web Page Generation in Jenkins | |||
| CVE-2017-2612 | unknown | — | — | 4y ago | Incorrect Permission Assignment for Critical Resource in Jenkins | |||
| CVE-2017-2613 | unknown | — | — | 4y ago | Cross-Site Request Forgery in Jenkins | |||
| CVE-2017-2603 | unknown | — | — | 4y ago | Exposure of Sensitive Information to an Unauthorized Actor in Jenkins | |||
| CVE-2017-2606 | unknown | — | — | 4y ago | Exposure of Sensitive Information to an Unauthorized Actor in Jenkins | |||
| CVE-2017-2638 | unknown | — | — | 4y ago | Infinispan Rest API Does Not Enforce Auth Constraints | |||
| CVE-2017-2649 | unknown | — | — | 4y ago | Jenkins Active Directory Plugin did not verify certificate of AD server | |||
| CVE-2017-2648 | unknown | — | — | 4y ago | Jenkins SSH Build Agents Plugin did not verify host keys | |||
| CVE-2017-2651 | unknown | — | — | 4y ago | Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin | |||
| CVE-2017-2654 | unknown | — | — | 4y ago | Emails were sent to addresses not associated with actual users of Jenkins by Email Extension Plugin | |||
| CVE-2017-2650 | unknown | — | — | 4y ago | Jenkins Pipeline Classpath Step plugin allowed Script Security sandbox bypass | |||
| CVE-2017-2652 | unknown | — | — | 4y ago | Missing permission checks in Jenkins Distributed Fork Plugin | |||
| CVE-2017-3203 | unknown | — | — | 4y ago | Deserialization of Untrusted Data in Spring-flex | |||
| CVE-2017-3202 | unknown | — | — | 4y ago | Deserialization of Untrusted Data in Flamingo amf-serializer |