Skip to main content

Year archive

CVEs published in 2017

Archive summary

14,642 CVEs published in 2017 — 2,108 Critical, 6,607 High, 5,693 Medium, 234 Low, 0 Unrated.

CVE-2017-17715

Published Dec 16, 2017

The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal via a pathname obtained in a file-transf…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14134

Published Dec 16, 2017

A Reflected XSS Vulnerability affects the forgotten password page of Maplesoft Maple T.A. 2016.0.6 (Customer Hosted) via the emailAddress parameter to passwordreset/PasswordReset.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-3195

Published Dec 16, 2017

Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arb…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-3194

Published Dec 16, 2017

Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM)…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3190

Published Dec 16, 2017

Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly validate SSL certificates provided by HTTPS connections, whic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-3186

Published Dec 16, 2017

ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC use non-random default credentials across all devices. A remote attacker can take compl…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-3185

Published Dec 16, 2017

ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC have a web application that uses the GET method to process requests that contain sensit…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-3184

Published Dec 16, 2017

ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset page. An unauthenticated, remote…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14093

Published Dec 16, 2017

The Log Query and Quarantine Query pages in Trend Micro ScanMail for Exchange 12.0 are vulnerable to cross site scripting (XSS) attacks.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-14092

Published Dec 16, 2017

The absence of Anti-CSRF tokens in Trend Micro ScanMail for Exchange 12.0 web interface forms could allow an attacker to submit authenticated requests when an authenticated user b…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14091

Published Dec 16, 2017

A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a uncommon feature - Other Update Sources - could be exploite…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14090

Published Dec 16, 2017

A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-11397

Published Dec 16, 2017

A service DLL preloading vulnerability in Trend Micro Encryption for Email versions 5.6 and below could allow an unauthenticated remote attacker to execute arbitrary code on a vul…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-10905

Published Dec 16, 2017

A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attackers to alter environment variables via unspecified vectors.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-10904

Published Dec 16, 2017

Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17712

Published Dec 16, 2017

The raw_sendmsg() function in net/ipv4/raw.c in the Linux kernel through 4.14.6 has a race condition in inet->hdrincl that leads to uninitialized stack pointer usage; this allows…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17701

Published Dec 15, 2017

K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025c8 DeviceIoControl request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17700

Published Dec 15, 2017

K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025a4 DeviceIoControl request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-17699

Published Dec 15, 2017

K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 476-500 of 14,642 CVEsPage 20 of 586