Skip to main content

Year archive

CVEs published in 2017

Archive summary

14,642 CVEs published in 2017 — 2,108 Critical, 6,607 High, 5,693 Medium, 234 Low, 0 Unrated.

CVE-2017-17800

Published Dec 20, 2017

In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17799

Published Dec 20, 2017

In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17798

Published Dec 20, 2017

In TG Soft Vir.IT eXplorer Lite 8.5.42, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17797

Published Dec 20, 2017

In IKARUS anti.virus 2.16.20, the driver file (ntguard.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17796

Published Dec 20, 2017

In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17795

Published Dec 20, 2017

In IKARUS anti.virus 2.16.20, the driver file (ntguard.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17794

Published Dec 20, 2017

validate_form_preferences in admin/preferences.php in BlogoText through 3.7.6 allows attackers to bypass intended access restrictions via vectors related to an e-mail address fiel…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17793

Published Dec 20, 2017

Information Disclosure vulnerability in creer_fichier_zip in admin/maintenance.php in BlogoText through 3.7.6 allows remote attackers to defeat a filename-randomization protection…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17792

Published Dec 20, 2017

Cross site scripting (XSS) vulnerability in the markup_clean_href function in inc/conv.php in BlogoText through 3.7.6 allows remote attackers to inject arbitrary JavaScript via a…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17790

Published Dec 20, 2017

The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 uses Kernel#open, which might allow Command Injection attacks, as demonstrated by a Resolv::Hosts::new argument…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17780

Published Dec 20, 2017

The Clockwork SMS clockwork-test-message.php component has XSS via a crafted "to" parameter in a clockwork-test-message request to wp-admin/admin.php. This component code is found…

CVSS 6.1 · Medium

CVE-2017-17775

Published Dec 20, 2017

Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 401-425 of 14,642 CVEsPage 17 of 586