Skip to main content

Year archive

CVEs published in 2017

Archive summary

14,642 CVEs published in 2017 — 2,108 Critical, 6,607 High, 5,693 Medium, 234 Low, 0 Unrated.

CVE-2017-17556

Published Dec 15, 2017

A debug tool in Synaptics TouchPad drivers allows local users with administrative access to obtain sensitive information about keyboard scan codes by modifying registry keys.

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-16776

Published Dec 15, 2017

Security researchers discovered an authentication bypass vulnerability in version 2.0.2 of the Conserus Workflow Intelligence application by McKesson Medical Imaging Company, whic…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-14101

Published Dec 15, 2017

A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, whi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15890

Published Dec 15, 2017

Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via t…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-17697

Published Dec 15, 2017

The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17405

Published Dec 15, 2017

Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the loc…

CVSS 8.8 · High

CVE-2017-16355

Published Dec 14, 2017

In agent/Core/SpawningKit/Spawner.h in Phusion Passenger 5.1.10 (fixed in Passenger Open Source 5.1.11 and Passenger Enterprise 5.1.10), if Passenger is running as root, it is pos…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5264

Published Dec 14, 2017

Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10703

Published Dec 14, 2017

A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, before version 2.0.0, allows a remote attacker to overload and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7344

Published Dec 14, 2017

A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Windows "security alert" dialog ther…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17535

Published Dec 14, 2017

lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17534

Published Dec 14, 2017

uiutil.c in Mensis 0.0.080507 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17533

Published Dec 14, 2017

default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argu…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17532

Published Dec 14, 2017

examples/framework/news/news3.py in Kiwi 1.9.22 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote atta…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17531

Published Dec 14, 2017

gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17530

Published Dec 14, 2017

common/help.c in Geomview 1.9.5 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-17529

Published Dec 14, 2017

af/util/xp/ut_go_file.cpp in AbiWord 3.0.2-2 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attacke…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 501-525 of 14,642 CVEsPage 21 of 586